logo

JUMPSEC Unmasks Iranian ‘Muddy Water’ Using Russian ‘CastleRAT’ Malware

ID: a23ed6ce-2150-5ee5-b302-8735fd6d800f

STIX ID: report--a23ed6ce-2150-5ee5-b302-8735fd6d800f

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

JUMPSEC researchers report that Iranian APT Muddy Water has operationally linked with the CastleRAT MaaS platform, deploying a JavaScript-based loader called ChainShell (delivered by reset.ps1) and hidden VNC (HVNC) to hijack browser sessions and bypass MFA; C2 resolution is handled via an Ethereum smart contract and native payloads were found steganographically embedded in JPEGs, indicating a sophisticated capability upgrade and active pre-staged operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.