logo

Iranian Cyber-Threat Group Drops New Backdoor, 'BugSleep'

ID: 8402d88a-fa8f-56ff-9f6c-47e626b8e6f5

STIX ID: report--8402d88a-fa8f-56ff-9f6c-47e626b8e6f5

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-07-18

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Iran-linked APT MuddyWater has transitioned from using legitimate remote-management software to delivering a custom backdoor called MuddyRot (also reported as BugSleep) via malicious PDFs hosted on file-sharing services such as Egnyte. The report highlights the implant's anti-analysis techniques, encryption and implementation bugs indicative of active development, and ongoing targeted phishing campaigns against government and critical-sector organizations across multiple countries in the Middle East and beyond.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.