logo

MuddyWater Uses Russian MaaS in New ChainShell Attack

ID: 121b9955-ceb1-5bb4-b265-e066a1aef3dd

STIX ID: report--121b9955-ceb1-5bb4-b265-e066a1aef3dd

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

JUMPSEC reports that Iran-linked espionage group MuddyWater has been using a Russian malware-as-a-service (TAG-150 / CastleRAT) ecosystem alongside a newly documented JavaScript/Node.js agent called “ChainShell” (which resolves C2 via an Ethereum smart contract) to target Israeli organizations; analysis includes samples, timestamps, certificate/JWT-based attribution, behavioral details, and IoCs (domains, IPs, and staging hosts) for defenders to investigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.