logo

MuddyWater replaces Atera by custom MuddyRot implant in a recent campaign

ID: 92cd93eb-6e0b-56b6-8e55-8fda5a2e3458

STIX ID: report--92cd93eb-6e0b-56b6-8e55-8fda5a2e3458

Feed Name: Sekoia.io Blog

Threat Score
78/100

Date Published: 2024-07-15

Date Updated: 2026-04-29

Author: Sekoia TDR

...
...

Sekoia TDR details a June 2024 MuddyWater campaign in which the actor replaced previously abused RMM tooling with a custom x64 implant dubbed "MuddyRot" delivered via malicious PDFs linking to Egnyte-hosted ZIPs; the report includes a technical breakdown of MuddyRot's string obfuscation, persistence via scheduled tasks, raw-TCP C2 on port 443 with obfuscated traffic, reverse-shell and file upload/download capabilities, supported command IDs, plus observed IOCs, infrastructure IPs and YARA rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.