logo

'MuddyWater' Hackers Target Israeli Orgs With Retro Game Tactic

ID: 1c611359-6326-53b6-99b9-90a5aaff1197

STIX ID: report--1c611359-6326-53b6-99b9-90a5aaff1197

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

MuddyWater (TA450), an Iran-linked APT, conducted a campaign from Sept. 30 to Mar. 18 targeting 18 organizations in Israel and one in Egypt, deploying a new Snake-inspired loader called Fooder that delays execution to evade sandboxes and reflectively loads the MuddyViper backdoor and stealer payloads; attackers used spear-phishing with PDF lures linking to RMM tools, leveraged Windows CNG for C2 communications, and demonstrated increased operational maturity and stealth despite operational clumsiness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.