Iran’s MuddyWater APT targets Saudis and Israelis with BugSleep Backdoor
ID: a128dcd3-9780-5225-882a-d7a933f33f91
STIX ID: report--a128dcd3-9780-5225-882a-d7a933f33f91
Feed Name: HackRead
Threat Score
Check Point and reporting sites uncovered a MuddyWater phishing campaign that deployed a custom backdoor called BugSleep against targets in Saudi Arabia and Israel. The report describes delivery via phishing lures and Egnyte file-sharing, sandbox-evasion using repeated Windows Sleep API calls, remote command and file-transfer capabilities to attacker-controlled C2, and evidence of iterative updates and targeted regional infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
