Catching fish in muddy waters
ID: 39448dd5-aa74-5622-9b02-47ae92d75b49
STIX ID: report--39448dd5-aa74-5622-9b02-47ae92d75b49
Feed Name: Group-IB Blog
This Group-IB analysis describes a series of leaks and active campaigns by Iran-linked APTs (OilRig/APT34 and MuddyWater) that exposed source code, victim lists, and operational infrastructure. The report details MuddyWater’s use of the POWERSTATS PowerShell backdoor, lists C2 servers and file hashes, and documents a targeted phishing campaign against Turkish defense contractor ASELSAN that leveraged decoy documents and previously leaked credentials while presenting potential attribution to individuals using the Gladiyator_CRK / Nima Nikjoo handles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
