Reborn in Rust: MuddyWater Evolves Tooling with RustyWater Implant
ID: d425a842-47d4-51f8-8e46-7c231078054c
STIX ID: report--d425a842-47d4-51f8-8e46-7c231078054c
Feed Name: CloudSEK Blog
**CloudSEK TRIAD identified a MuddyWater spearphishing campaign targeting Middle East diplomatic, maritime, financial, and telecom sectors that uses a malicious Word document with embedded macros to drop a Rust-based implant (RustyWater/Archer RAT) capable of anti-analysis, registry persistence, async HTTP C2, process injection, and modular post-compromise extension; the report provides technical analysis, IOCs (SHA256 hashes and IPs), MITRE mappings, and mitigation recommendations.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
