Iranian hackers targeted over 100 govt orgs with Phoenix backdoor
ID: d7ccbb39-39e5-57c3-92bb-3248292be8c3
STIX ID: report--d7ccbb39-39e5-57c3-92bb-3248292be8c3
Feed Name: Bleeping Computer
Group-IB reports that Iranian-linked APT MuddyWater conducted a phishing campaign beginning August 19 that targeted over 100 government and diplomatic organizations in the Middle East and North Africa, delivering malicious Word documents with macros that installed a FakeUpdate loader which decrypted and deployed Phoenix backdoor v4 (written to C:\ProgramData\sysprocupdate.exe) and a Chrome-family infostealer; the campaign used WinHTTP C2 communications, COM-based persistence, and additional tooling (PDQ, Action1), and Group-IB attributes the activity to MuddyWater with high confidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
