New BugSleep malware implant deployed in MuddyWater attacks
ID: f918a320-d6e5-5e19-b981-215fe226bd7f
STIX ID: report--f918a320-d6e5-5e19-b981-215fe226bd7f
Feed Name: Bleeping Computer
The Iranian-backed APT MuddyWater has begun deploying a newly discovered backdoor called BugSleep via well-crafted phishing emails that redirect victims to Egnyte-hosted malicious archives; BugSleep (still under active development) steals files, executes commands, and is sometimes delivered with a loader that injects into popular processes, marking a shift from the group’s prior use of legitimate RMM tools and affecting governments, airlines, media outlets and other organizations worldwide.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
