Iran's MuddyWater phishes Israeli orgs with custom BugSleep backdoor
ID: f86b66be-982f-5355-b29d-d4487925377a
STIX ID: report--f86b66be-982f-5355-b29d-d4487925377a
Feed Name: The Register (Security)
Threat Score
Check Point Research reports that MuddyWater, an Iranian government-backed APT, has begun deploying a bespoke backdoor named "BugSleep" via phishing emails (often from compromised organizational accounts) targeting Israeli organizations and other regional targets; analyzed samples show scheduled-task persistence, data exfiltration routines, evasion techniques, and a custom shellcode loader, indicating an active, capable espionage campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
