logo

DarkBeatC2: The Latest MuddyWater Attack Framework

ID: df0f6e57-cdb7-51c1-b678-adf3a7194d73

STIX ID: report--df0f6e57-cdb7-51c1-b678-adf3a7194d73

Feed Name: Deep Instinct Blog

Threat Score
85/100

Date Published: 2024-04-04

Date Updated: 2026-04-27

Author: Simon Kenin

...
...

Deep Instinct analysts describe increased Iranian state-aligned cyber activity against Israeli organisations, highlighting supply-chain intrusions (compromise of IT provider 'Rashim' and the 'Lord Nemesis' faketivist campaign), attribution and hand-offs among Iranian groups, and the discovery of a suspected MuddyWater C2 framework named 'DarkBeatC2'. The report includes PowerShell C2 snippets, analysis of how the C2 operates, related abuse of RMM tools, and an indicators appendix listing IPs and file hashes to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.