logo

Unmasking an Attack Chain of MuddyWater

ID: 698a56ff-c76a-598c-a385-04fc0c230435

STIX ID: report--698a56ff-c76a-598c-a385-04fc0c230435

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

...
...

Huntress investigated a confirmed intrusion attributed to an Iranian-linked APT (MuddyWater) where the attacker gained RDP access to a customer host, created an SSH reverse tunnel, and performed DLL side-loading of a malicious FMAPP.dll via the legitimate FMAPP.exe to establish C2; the report provides a timeline of commands, verification attempts, and IOCs including IPs, username, file paths and SHA256 hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.