logo

RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants

ID: b54de7e8-ee3f-54b4-ad0c-871af87093e8

STIX ID: report--b54de7e8-ee3f-54b4-ad0c-871af87093e8

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

CloudSEK’s TRIAD team reports that the MuddyWater APT has adopted a new Rust-based implant named “RustyWater,” deployed via spearphishing Word documents with malicious macros that drop an executable and install a modular Rust RAT providing asynchronous C2, anti-analysis, registry persistence, and post-compromise modules; this represents a shift from the group’s historical PowerShell/VBS tooling toward more stealthy, cross-platform compiled malware targeting diplomatic, maritime, financial and telecom entities in the Middle East.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.