MuddyWater: ClickFix to Telegram & PatchAgent Backdoor
ID: e827cec3-b8bc-5d08-ad58-f9d165dcf78c
STIX ID: report--e827cec3-b8bc-5d08-ad58-f9d165dcf78c
Feed Name: Ransomware ISAC Blog
Date Published: 2026-07-15
Date Updated: 2026-08-21
Author: [email protected] (Ransom-ISAC Research Team)
This report documents a recently active, sophisticated three-stage loader (cloud.dll → wuaupdt.exe → PTCH-encrypted shellcode) termed PatchAgent that decrypts a position-independent x64 HTTP backdoor which beacons to 46.30.188.99 and supports PowerShell execution, process hollowing into notepad.exe, persistence via Run keys and COM hijack, and self-removal; the authors link the toolset to the MuddyWater group with high confidence and provide extensive IOCs, infrastructure pivots (notably 185.228.83.217 and ClickFix/WebDAV delivery), cryptographic material, and detection/hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
