logo

Iran's 'MuddyWater' Levels Up With MuddyViper Backdoor

ID: 678a9107-6b99-5cdd-8378-01054dd9529b

STIX ID: report--678a9107-6b99-5cdd-8378-01054dd9529b

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-12-02

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

MuddyWater (TA450) conducted a stealthier, more sophisticated cyber-espionage campaign from late September 2024 to mid-March 2025 targeting mainly Israeli organizations (with at least one Egyptian victim). The operation used a new in-memory 64-bit loader called "Fooder," a custom backdoor "MuddyViper," and multiple credential stealers (CE-Notes, LP-Notes, Blub) to harvest credentials, exfiltrate data via reverse tunnels, and maintain persistence, with evidence of improved development capabilities and possible collaboration with Lyceum/OilRig.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.