logo

MuddyWater: ClickFix to Telegram & PatchAgent Backdoor

ID: 393c78e4-36b1-55e4-9be2-420e18066342

STIX ID: report--393c78e4-36b1-55e4-9be2-420e18066342

Feed Name: Ransomware ISAC Blog

Threat Score
88/100

Date Published: 2026-07-15

Date Updated: 2026-07-29

Author: [email protected] (Ransom-ISAC Research Team)

...
...

**Executive summary:** This report dissects a purpose-built, three-stage PatchAgent loader chain (COM DLL dropper → loader → PTCH v2 AES/HMAC-encrypted shellcode) that decrypts and runs a position-independent x64 HTTP backdoor beaconing to 46.30.188.99; it provides sample metadata, recovered cryptographic keys, IOCs, infrastructure pivots (including ClickFix WebDAV delivery on 185.228.83.217), MITRE ATT&CK mapping, and prioritized detection/hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.