Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks
ID: 901b2588-864c-5bf5-a79b-9d4f224b3c38
STIX ID: report--901b2588-864c-5bf5-a79b-9d4f224b3c38
Feed Name: The Hacker News
Proofpoint observed an active March 2024 phishing campaign by Iran-affiliated MuddyWater (TA450) targeting Israeli organizations; attackers used PDFs with embedded links to file-sharing hosts that delivered ZIP archives containing MSI installers that installed the legitimate Atera RMM agent for remote access. Separately, hacktivist group Lord Nemesis exploited credentials from a Rashim Software breach to access multiple academic customers, harvest personal data, and notify over 200 affected customers, underscoring supply-chain and third-party risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
