logo

MuddyWater’s Sneaky New Tactic: Hijacking RMM Software for Espionage

ID: c3488e51-6c52-54c9-889d-572cfdcb73b6

STIX ID: report--c3488e51-6c52-54c9-889d-572cfdcb73b6

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2024-09-06

Date Updated: 2026-04-22

Author: do son

...
...

MuddyWater (an Iranian APT active since 2017) is leveraging legitimate RMM tools delivered via phishing (malicious attachments disguised as Arabic documents) to obtain remote access, perform lateral movement, and conduct espionage against government, military, telecom, and oil sector organizations across the Middle East, Europe, and North America; use of trusted RMM software (Remote Utilities, ScreenConnect, Atera, Syncro) makes detection difficult and increases risk to targeted organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.