Iranian Group MuddyWater Deploys MuddyRot Malware in New Campaign
ID: dee1260c-0b9e-58de-bf1c-9d7b5f9008c3
STIX ID: report--dee1260c-0b9e-58de-bf1c-9d7b5f9008c3
Feed Name: The Cyber Express
Threat Score
MuddyWater, an Iranian-linked APT, has deployed a custom backdoor called MuddyRot in a campaign targeting multiple Middle Eastern and Western organizations by exploiting internet-facing services and distributing malicious PDFs; the implant provides persistence, reverse shell, file transfer and obfuscated TCP C2 communications, and researchers have published IOCs and analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
