logo

Iranian hackers targeted over 100 govt orgs with Phoenix backdoor

ID: d7ccbb39-39e5-57c3-92bb-3248292be8c3

STIX ID: report--d7ccbb39-39e5-57c3-92bb-3248292be8c3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-22

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Group-IB reports that Iranian-linked APT MuddyWater conducted a phishing campaign beginning August 19 that targeted over 100 government and diplomatic organizations in the Middle East and North Africa, delivering malicious Word documents with macros that installed a FakeUpdate loader which decrypted and deployed Phoenix backdoor v4 (written to C:\ProgramData\sysprocupdate.exe) and a Chrome-family infostealer; the campaign used WinHTTP C2 communications, COM-based persistence, and additional tooling (PDQ, Action1), and Group-IB attributes the activity to MuddyWater with high confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.