MuddyWater-Style Hackers Scan 12,000+ Systems Before Hitting Middle East Critical Sectors
ID: 664076dd-1d3b-5ac0-8461-b6196ed8bcd8
STIX ID: report--664076dd-1d3b-5ac0-8461-b6196ed8bcd8
Feed Name: cybersecurityNews.com
A sophisticated APT-like campaign, attributed to actors resembling MuddyWater, scanned over 12,000 internet-exposed systems and exploited five weaponized CVEs (including Laravel Livewire, SmarterMail, n8n, RMM session ID, and Langflow) to gain access to organizations across the Middle East, India, and Portugal. Operators performed OWA brute-force credential harvesting using custom tools, staged roughly 200 files containing passports, payroll, and payment data, and exfiltrated sensitive aviation data from an Egyptian target; analysis uncovered modular TCP/UDP and AES-encrypted HTTP C2 infrastructure traced to 157.20.182.49 and provided actionable remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
