logo

Catching fish in muddy waters

ID: 39448dd5-aa74-5622-9b02-47ae92d75b49

STIX ID: report--39448dd5-aa74-5622-9b02-47ae92d75b49

Feed Name: Group-IB Blog

Threat Score
85/100

Date Published: 2019-05-29

Date Updated: 2026-04-27

...
...

This Group-IB analysis describes a series of leaks and active campaigns by Iran-linked APTs (OilRig/APT34 and MuddyWater) that exposed source code, victim lists, and operational infrastructure. The report details MuddyWater’s use of the POWERSTATS PowerShell backdoor, lists C2 servers and file hashes, and documents a targeted phishing campaign against Turkish defense contractor ASELSAN that leveraged decoy documents and previously leaked credentials while presenting potential attribution to individuals using the Gladiyator_CRK / Nima Nikjoo handles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.