logo

Iran’s MuddyWater APT targets Saudis and Israelis with BugSleep Backdoor

ID: a128dcd3-9780-5225-882a-d7a933f33f91

STIX ID: report--a128dcd3-9780-5225-882a-d7a933f33f91

Feed Name: HackRead

Threat Score
78/100

Date Published: 2024-07-16

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Check Point and reporting sites uncovered a MuddyWater phishing campaign that deployed a custom backdoor called BugSleep against targets in Saudi Arabia and Israel. The report describes delivery via phishing lures and Egnyte file-sharing, sandbox-evasion using repeated Windows Sleep API calls, remote command and file-transfer capabilities to attacker-controlled C2, and evidence of iterative updates and targeted regional infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.