logo

Boggy Serpens Hits Diplomats, Critical Infrastructure in Espionage Waves

ID: 9d388806-30ee-5d08-805c-55315eeef086

STIX ID: report--9d388806-30ee-5d08-805c-55315eeef086

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Boggy Serpens (aka MuddyWater) has shifted to stealthy, persistence-focused campaigns targeting diplomats and critical infrastructure across the Middle East, Europe, Central/Western Asia and South America, using hijacked trusted accounts and tailored social engineering to deliver macro-laden Office documents that deploy a growing Rust- and Python-based toolset (BlackBeard, Nuso, UDPGangster, LampoRAT) and HTTP/UDP C2 techniques; the report includes timelineed campaign waves, IoCs (SHA256 hashes, an IP), and mitigation guidance (macro restrictions, identity/mailflow hardening, behavioral analytics).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.