logo

Iranian Hackers Using MuddyC2Go in Telecom Espionage Attacks Across Africa

ID: f6c222fb-2c52-56c1-879c-95fc40881d27

STIX ID: report--f6c222fb-2c52-56c1-879c-95fc40881d27

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2023-12-19

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Executive summary: Symantec/Broadcom observes the Iranian APT MuddyWater (Seedworm) deploying a newly identified Golang C2 framework (MuddyC2Go) in November 2023 attacks against telecommunications organizations in Egypt, Sudan, and Tanzania; intrusions combined bespoke malware (custom keylogger, MuddyC2Go), living‑off‑the‑land techniques (PowerShell), and legitimate remote‑access tools (SimpleHelp, AnyDesk, JumpCloud) to maintain persistence and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.