logo

MuddyWater Hackers Using UDPGangster Backdoor to Attack Windows Systems Evading Network Defenses

ID: 0455fb9d-9ab1-5280-ba63-ad516d0a1248

STIX ID: report--0455fb9d-9ab1-5280-ba63-ad516d0a1248

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** The MuddyWater APT is running active campaigns across Turkey, Israel, and Azerbaijan using weaponized Word documents with VBA macros to deploy a UDP-based backdoor named UDPGangster; the malware includes robust anti-analysis checks, establishes persistence via %AppData% and registry startup entries, and communicates stealthily with a known C2 (157.20.182.75) over UDP port 1269.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.