Iranian Cyber-Threat Group Drops New Backdoor, 'BugSleep'
ID: 8402d88a-fa8f-56ff-9f6c-47e626b8e6f5
STIX ID: report--8402d88a-fa8f-56ff-9f6c-47e626b8e6f5
Feed Name: Dark Reading
Iran-linked APT MuddyWater has transitioned from using legitimate remote-management software to delivering a custom backdoor called MuddyRot (also reported as BugSleep) via malicious PDFs hosted on file-sharing services such as Egnyte. The report highlights the implant's anti-analysis techniques, encryption and implementation bugs indicative of active development, and ongoing targeted phishing campaigns against government and critical-sector organizations across multiple countries in the Middle East and beyond.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
