logo

Iranian MuddyWater Hackers Adopt New C2 Tool 'DarkBeatC2' in Latest Campaign

ID: fb96f548-cdc3-5bd4-ad34-1a1f19a7b3b3

STIX ID: report--fb96f548-cdc3-5bd4-ad34-1a1f19a7b3b3

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-04-12

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

The report details Iranian-linked APT activity: MuddyWater is using a newly identified C2 infrastructure called DarkBeatC2 to manage victims through PowerShell-based agents, DLL side‑loading, scheduled tasks, and registry AutodialDLL abuse after spear-phishing delivery (notably via Atera Agent installers possibly distributed through a breached academic customer). Separately, Unit 42 analyzed the FalseFont backdoor used by Peach Sandstorm to harvest credentials and system data via a faux recruitment GUI, highlighting targeted attacks against aerospace and defense organizations and the potential collaboration or hand-off between IRGC- and MOIS-linked groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.