logo

MuddyWater APT Weaponizing Word Documents to Deliver ‘RustyWater’ Toolkit Evading AV and EDR Tools

ID: a7dbcd35-715c-5d75-b442-3fa62933738d

STIX ID: report--a7dbcd35-715c-5d75-b442-3fa62933738d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

CloudSEK researchers discovered a MuddyWater spear-phishing campaign targeting diplomatic, maritime, financial, and telecom sectors in the Middle East that uses malicious Word documents with VBA macros to drop a new Rust-based implant called RustyWater. The implant persists via a ProgramData drop (CertificationKit.ini) and Run registry entry, employs XOR/string obfuscation and checks for >25 AV/EDR products to evade detection, collects host metadata, encodes/exfiltrates it to C2 servers using the Rust reqwest library, and randomizes sleep and network behavior to blend in.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.