MuddyWater APT Weaponizing Word Documents to Deliver ‘RustyWater’ Toolkit Evading AV and EDR Tools
ID: a7dbcd35-715c-5d75-b442-3fa62933738d
STIX ID: report--a7dbcd35-715c-5d75-b442-3fa62933738d
Feed Name: cybersecurityNews.com
CloudSEK researchers discovered a MuddyWater spear-phishing campaign targeting diplomatic, maritime, financial, and telecom sectors in the Middle East that uses malicious Word documents with VBA macros to drop a new Rust-based implant called RustyWater. The implant persists via a ProgramData drop (CertificationKit.ini) and Run registry entry, employs XOR/string obfuscation and checks for >25 AV/EDR products to evade detection, collects host metadata, encodes/exfiltrates it to C2 servers using the Rust reqwest library, and randomizes sleep and network behavior to blend in.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
