logo

Tracking MuddyWater in Action: Infrastructure, Malware and Operations during 2025

ID: edc566ca-8f95-5c52-9f63-d59e6dab3dc9

STIX ID: report--edc566ca-8f95-5c52-9f63-d59e6dab3dc9

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2025-09-17

Date Updated: 2026-04-28

...
...

Group-IB details that MuddyWater, an Iran-nexus APT, remains active and increasingly sophisticated—shifting from opportunistic RMM abuse to targeted spearphishing with malicious Office documents and custom backdoors (BugSleep, StealthCache, Phoenix) and loaders (Fooder). The report includes technical malware behavior, C2 communication patterns, hosting and certificate pivots (AWS, Cloudflare, bulletproof hosts), sample IOCs, hunting techniques, and mitigation recommendations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.