RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants
ID: b54de7e8-ee3f-54b4-ad0c-871af87093e8
STIX ID: report--b54de7e8-ee3f-54b4-ad0c-871af87093e8
Feed Name: securityonline.info
CloudSEK’s TRIAD team reports that the MuddyWater APT has adopted a new Rust-based implant named “RustyWater,” deployed via spearphishing Word documents with malicious macros that drop an executable and install a modular Rust RAT providing asynchronous C2, anti-analysis, registry persistence, and post-compromise modules; this represents a shift from the group’s historical PowerShell/VBS tooling toward more stealthy, cross-platform compiled malware targeting diplomatic, maritime, financial and telecom entities in the Middle East.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
