Tracking MuddyWater in Action: Infrastructure, Malware and Operations during 2025
ID: edc566ca-8f95-5c52-9f63-d59e6dab3dc9
STIX ID: report--edc566ca-8f95-5c52-9f63-d59e6dab3dc9
Feed Name: Group-IB Blog
Group-IB details that MuddyWater, an Iran-nexus APT, remains active and increasingly sophisticated—shifting from opportunistic RMM abuse to targeted spearphishing with malicious Office documents and custom backdoors (BugSleep, StealthCache, Phoenix) and loaders (Fooder). The report includes technical malware behavior, C2 communication patterns, hosting and certificate pivots (AWS, Cloudflare, bulletproof hosts), sample IOCs, hunting techniques, and mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
