logo

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks

ID: 901b2588-864c-5bf5-a79b-9d4f224b3c38

STIX ID: report--901b2588-864c-5bf5-a79b-9d4f224b3c38

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Proofpoint observed an active March 2024 phishing campaign by Iran-affiliated MuddyWater (TA450) targeting Israeli organizations; attackers used PDFs with embedded links to file-sharing hosts that delivered ZIP archives containing MSI installers that installed the legitimate Atera RMM agent for remote access. Separately, hacktivist group Lord Nemesis exploited credentials from a Rashim Software breach to access multiple academic customers, harvest personal data, and notify over 200 affected customers, underscoring supply-chain and third-party risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.