logo

Reborn in Rust: MuddyWater Evolves Tooling with RustyWater Implant

ID: d425a842-47d4-51f8-8e46-7c231078054c

STIX ID: report--d425a842-47d4-51f8-8e46-7c231078054c

Feed Name: CloudSEK Blog

Threat Score
88/100

Date Published: 2026-01-08

Date Updated: 2026-04-27

...
...

**CloudSEK TRIAD identified a MuddyWater spearphishing campaign targeting Middle East diplomatic, maritime, financial, and telecom sectors that uses a malicious Word document with embedded macros to drop a Rust-based implant (RustyWater/Archer RAT) capable of anti-analysis, registry persistence, async HTTP C2, process injection, and modular post-compromise extension; the report provides technical analysis, IOCs (SHA256 hashes and IPs), MITRE mappings, and mitigation recommendations.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.