logo

MuddyWater: Snakes by the riverbank

ID: 57ebad0f-86fa-5a07-a69a-b0fb2a5ac25a

STIX ID: report--57ebad0f-86fa-5a07-a69a-b0fb2a5ac25a

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
88/100

Date Published: 2025-12-02

Date Updated: 2026-05-01

...
...

ESET documents a MuddyWater (Iran-aligned) espionage campaign that deployed previously undocumented tooling — notably the Fooder reflective loader (masquerading as a Snake game) and the MuddyViper C/C++ backdoor — alongside credential and browser stealers (CE-Notes, LP-Notes, Blub) and go-socks5 reverse tunnels; the report details techniques (CNG-based encryption, reflective loading, sleep-based sandbox evasion), victimology (primarily Israeli organizations, one in Egypt), MITRE ATT&CK mappings, and a comprehensive list of file and network IoCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.