MuddyWater Exposed: Inside an Iranian APT operation
ID: 1b6b107f-f6e3-58ba-8aa2-66cfb326c52e
STIX ID: report--1b6b107f-f6e3-58ba-8aa2-66cfb326c52e
Feed Name: Ctrl-Alt-Int3l
Ctrl-Alt-Intel uncovered exposed infrastructure and operational artifacts belonging to MuddyWater (an Iranian APT), recovering multiple custom C2 frameworks, malware loaders (including a Node.js/Ethereum-based Tsundere bot), exploitation tooling for numerous CVEs (Fortinet, Ivanti, Exchange, etc.), and evidence of data exfiltration affecting organizations across Israel, Jordan, Egypt, UAE, Portugal and the US; the report provides IOCs, MITRE ATT&CK mappings, and attribution rationale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
