Iranian MuddyWater Hackers Adopt New C2 Tool 'DarkBeatC2' in Latest Campaign
ID: fb96f548-cdc3-5bd4-ad34-1a1f19a7b3b3
STIX ID: report--fb96f548-cdc3-5bd4-ad34-1a1f19a7b3b3
Feed Name: The Hacker News
The report details Iranian-linked APT activity: MuddyWater is using a newly identified C2 infrastructure called DarkBeatC2 to manage victims through PowerShell-based agents, DLL side‑loading, scheduled tasks, and registry AutodialDLL abuse after spear-phishing delivery (notably via Atera Agent installers possibly distributed through a breached academic customer). Separately, Unit 42 analyzed the FalseFont backdoor used by Peach Sandstorm to harvest credentials and system data via a faux recruitment GUI, highlighting targeted attacks against aerospace and defense organizations and the potential collaboration or hand-off between IRGC- and MOIS-linked groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
