logo

Inside a MuddyWater Intrusion: Exploitation of SharePoint and Living-Off-the-Land Tactics

ID: f2702bea-168d-5cda-b1cb-a1685bb6c1c7

STIX ID: report--f2702bea-168d-5cda-b1cb-a1685bb6c1c7

Feed Name: Kudelski Security

Threat Score
90/100

Date Published: 2025-09-17

Date Updated: 2026-07-22

...
...

In late August 2025 an IR team investigated a targeted MuddyWater (Static Kitten) intrusion that exploited SharePoint CVE-2025-53770 to deploy file-management webshells and attempt to load a PowerShell RAT; the adversary escalated privileges with GodPotato, dumped LSASS, moved laterally using Invoke-SMBExec and WMI, abused AnyDesk and PDQ for persistence, deployed a custom TLS-resocks tunnel (FMAPP.exe / FMAPP.dll) for pivoting, and exfiltrated archived credential artifacts via the SharePoint server; the report contains technical analysis, IOCs (IPs, SHA256, domains), and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.