Unmasking an Attack Chain of MuddyWater
ID: 698a56ff-c76a-598c-a385-04fc0c230435
STIX ID: report--698a56ff-c76a-598c-a385-04fc0c230435
Feed Name: Huntress Blog
Threat Score
Huntress investigated a confirmed intrusion attributed to an Iranian-linked APT (MuddyWater) where the attacker gained RDP access to a customer host, created an SSH reverse tunnel, and performed DLL side-loading of a malicious FMAPP.dll via the legitimate FMAPP.exe to establish C2; the report provides a timeline of commands, verification attempts, and IOCs including IPs, username, file paths and SHA256 hashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
