Iranian Espionage Operations Linked To CastleRAT and ChainShell Malware Suite
ID: 45f6ec2e-9d13-5b91-98a4-d96a3f518480
STIX ID: report--45f6ec2e-9d13-5b91-98a4-d96a3f518480
Feed Name: Cyber Press
Threat Score
Intelligence links Iran’s MuddyWater APT to the Russian TAG-150 CastleRAT platform and a new Node.js backdoor called ChainShell; investigators found an exposed C2 with Farsi comments, Israeli target IPs, a malicious PowerShell installer (reset.ps1), shared code-signing certificates ("Amy Cherne"), steganographic JPEG payloads, and campaign identifiers, indicating MuddyWater’s active use of commercial MaaS to conduct resilient espionage against defense, aerospace, and energy targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
