MuddyWater-Style Hackers Probe 12,000+ Systems Ahead of Middle East
ID: 85a09718-f71e-5595-8077-991ba3ecc605
STIX ID: report--85a09718-f71e-5595-8077-991ba3ecc605
Feed Name: GBHackers
Oasis Security reports a MuddyWater-like, multi-stage campaign targeting Middle Eastern aviation, energy, and government organizations: attackers scanned ~12,000 internet-facing systems, exploited at least five disclosed CVEs (including Laravel Livewire, SmarterMail, n8n, Langflow and a session ID flaw), performed OWA brute-force credential harvesting, and used modular Python/Go C2 infrastructure (including controllers like `tcp_serv.py`, `udp_3.0.py` and an `ex-server` at 157.20.182.49) to achieve persistent access and exfiltrate sensitive data (passport/visa records, payroll, credit card info) from at least one Egyptian aviation company.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
