MuddyWater Hackers Using UDPGangster Backdoor to Attack Windows Systems Evading Network Defenses
ID: 0455fb9d-9ab1-5280-ba63-ad516d0a1248
STIX ID: report--0455fb9d-9ab1-5280-ba63-ad516d0a1248
Feed Name: cybersecurityNews.com
Threat Score
**Executive summary:** The MuddyWater APT is running active campaigns across Turkey, Israel, and Azerbaijan using weaponized Word documents with VBA macros to deploy a UDP-based backdoor named UDPGangster; the malware includes robust anti-analysis checks, establishes persistence via %AppData% and registry startup entries, and communicates stealthily with a known C2 (157.20.182.75) over UDP port 1269.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
