Inside a MuddyWater Intrusion: Exploitation of SharePoint and Living-Off-the-Land Tactics
ID: f2702bea-168d-5cda-b1cb-a1685bb6c1c7
STIX ID: report--f2702bea-168d-5cda-b1cb-a1685bb6c1c7
Feed Name: Kudelski Security
In late August 2025 an IR team investigated a targeted MuddyWater (Static Kitten) intrusion that exploited SharePoint CVE-2025-53770 to deploy file-management webshells and attempt to load a PowerShell RAT; the adversary escalated privileges with GodPotato, dumped LSASS, moved laterally using Invoke-SMBExec and WMI, abused AnyDesk and PDQ for persistence, deployed a custom TLS-resocks tunnel (FMAPP.exe / FMAPP.dll) for pivoting, and exfiltrated archived credential artifacts via the SharePoint server; the report contains technical analysis, IOCs (IPs, SHA256, domains), and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
