logo

Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks

ID: 33d954c5-3edd-5656-90d7-b91fcb24290a

STIX ID: report--33d954c5-3edd-5656-90d7-b91fcb24290a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-07-16

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

MuddyWater (TA450), an Iran-linked nation-state actor, has shifted from abusing legitimate RMM tools to deploying a new bespoke x64 backdoor called BugSleep (aka MuddyRot) in recent spear-phishing campaigns. The implant, observed by Check Point and Sekoia, provides file upload/download, reverse shell, and persistence and communicates with a C2 over raw TCP on port 443; attacks use compromised business email accounts and Egnyte-hosted links/PDFs to deliver payloads, affecting countries across the Middle East and beyond.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.