logo

UDPGangster Campaigns Target Multiple Countries

ID: e99cd94a-0974-5178-a475-4c011337d866

STIX ID: report--e99cd94a-0974-5178-a475-4c011337d866

Feed Name: Fortinet Blog

Threat Score
80/100

Date Published: 2025-12-04

Date Updated: 2026-04-27

...
...

FortiGuard Labs details UDPGangster, a UDP-based backdoor used in targeted phishing campaigns attributed to the MuddyWater group that delivered the malware via macro-enabled Microsoft Word documents targeting Turkey, Israel, and Azerbaijan. The report describes the macro dropper, persistence (copying to %AppData%\RoamingLow as SystemProc.exe and registry startup), numerous anti-analysis and sandbox-detection techniques, C2 communication (notably 157.20.182.75:1269), supported remote commands, and provides IOCs and Fortinet detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.