logo

Iranian Espionage Operations Linked To CastleRAT and ChainShell Malware Suite

ID: 45f6ec2e-9d13-5b91-98a4-d96a3f518480

STIX ID: report--45f6ec2e-9d13-5b91-98a4-d96a3f518480

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Varshini

...
...

Intelligence links Iran’s MuddyWater APT to the Russian TAG-150 CastleRAT platform and a new Node.js backdoor called ChainShell; investigators found an exposed C2 with Farsi comments, Israeli target IPs, a malicious PowerShell installer (reset.ps1), shared code-signing certificates ("Amy Cherne"), steganographic JPEG payloads, and campaign identifiers, indicating MuddyWater’s active use of commercial MaaS to conduct resilient espionage against defense, aerospace, and energy targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.