logo

MuddyWater: ClickFix to Telegram & PatchAgent Backdoor

ID: e827cec3-b8bc-5d08-ad58-f9d165dcf78c

STIX ID: report--e827cec3-b8bc-5d08-ad58-f9d165dcf78c

Feed Name: Ransomware ISAC Blog

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-08-21

Author: [email protected] (Ransom-ISAC Research Team)

...
...

This report documents a recently active, sophisticated three-stage loader (cloud.dll → wuaupdt.exe → PTCH-encrypted shellcode) termed PatchAgent that decrypts a position-independent x64 HTTP backdoor which beacons to 46.30.188.99 and supports PowerShell execution, process hollowing into notepad.exe, persistence via Run keys and COM hijack, and self-removal; the authors link the toolset to the MuddyWater group with high confidence and provide extensive IOCs, infrastructure pivots (notably 185.228.83.217 and ClickFix/WebDAV delivery), cryptographic material, and detection/hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.