MuddyWater’s Sneaky New Tactic: Hijacking RMM Software for Espionage
ID: c3488e51-6c52-54c9-889d-572cfdcb73b6
STIX ID: report--c3488e51-6c52-54c9-889d-572cfdcb73b6
Feed Name: securityonline.info
MuddyWater (an Iranian APT active since 2017) is leveraging legitimate RMM tools delivered via phishing (malicious attachments disguised as Arabic documents) to obtain remote access, perform lateral movement, and conduct espionage against government, military, telecom, and oil sector organizations across the Middle East, Europe, and North America; use of trusted RMM software (Remote Utilities, ScreenConnect, Atera, Syncro) makes detection difficult and increases risk to targeted organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
