Threats Feed
- Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.
read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
MuddyWater Adopts Rust-Based RustyWater Implant in Middle East Espionage Campaign
CloudSEK identified a spearphishing campaign attributed to the MuddyWater APT group targeting diplomatic, maritime, financial, telecom, education, and shipping sectors across the Middle East, including Turkmenistan, the UAE, and regional maritime organizations. The operation uses impersonated government and telecom emails to deliver malicious Word documents embedding obfuscated VBA macros. These macros drop and execute a Rust-based implant dubbed RustyWater, which provides asynchronous HTTP C2, registry persistence, anti-analysis features, and modular post-compromise capabilities. The shift from PowerShell and VBS loaders to a Rust RAT marks a significant evolution in MuddyWater’s tooling toward stealthier, long-term espionage operations.
read more about MuddyWater Adopts Rust-Based RustyWater Implant in Middle East Espionage Campaign - Public
MuddyWater Targets Israeli Organizations with Custom BlackBeard Backdoor
The Iranian threat group MuddyWater recently launched highly targeted phishing campaigns against Israeli organizations, utilizing compromised corporate email accounts to distribute malicious macro-enabled Word documents. The attacks rely on localized social engineering, featuring tailored Hebrew content, legitimate branding, and lookalike domains. Upon execution, the campaign deploys "BlackBeard," a custom Rust-based backdoor capable of EDR evasion, system reconnaissance, and downloading additional payloads via encrypted HTTPS channels. Persistence is achieved through stealthy file association hijacking. The threat actors then leverage the newly compromised accounts to conduct internal spearphishing, enabling rapid lateral movement. This campaign demonstrates MuddyWater's persistent cyber espionage efforts and sophisticated tactical adaptations.
read more about MuddyWater Targets Israeli Organizations with Custom BlackBeard Backdoor - Public
MuddyWater Deploys New Toolset in Targeted Attacks on Israel and Egypt
ESET researchers uncovered a new MuddyWater campaign targeting organizations in Israel and one in Egypt, primarily within the telecommunications, government, oil and energy, and manufacturing sectors. The Iran-aligned group deployed a suite of newly developed tools, including the Fooder reflective loader and MuddyViper, a C/C++ backdoor capable of credential theft, system reconnaissance, and file operations. Additional stealers such as CE-Notes, LP-Notes, and Blub, along with customized go-socks5 reverse tunnels, enhanced persistence and defense evasion. The campaign also revealed operational overlap with Lyceum, indicating MuddyWater’s role as an initial access broker. Activity ran from September 30, 2024 to March 18, 2025.
read more about MuddyWater Deploys New Toolset in Targeted Attacks on Israel and Egypt - Public
Iranian APTs Exploit PaperCut Vulnerability in Global Cyber Attacks
On May 5–8, 2023, Microsoft Threat Intelligence reported that two Iranian state-backed groups had joined an ongoing wave of attacks targeting CVE-2023-27350, a pre-authentication critical remote code execution vulnerability (CVSS 9.8) in PaperCut MF and NG print management software versions 8.0 and later. The two groups are Mango Sandstorm (also known as Mercury or MuddyWater, linked to Iran's Ministry of Intelligence and Security/MOIS) and Mint Sandstorm (also known as Phosphorus or APT35, linked to Iran's Islamic Revolutionary Guard Corps/IRGC). Mint Sandstorm's exploitation was characterized as opportunistic, targeting organizations across multiple sectors and geographies without specific victim selection. Mango Sandstorm's activity was lower-volume, with operators reusing tools from prior intrusions to connect to existing C2 infrastructure — indicating the group was extending rather than initiating campaigns. The vulnerability had been disclosed in March 2023; public PoC exploits were released shortly after, enabling rapid threat actor adoption. Earlier exploitation was attributed to Lace Tempest (linked to Clop ransomware) and separately led to LockBit ransomware deployments. CISA added CVE-2023-27350 to its Known Exploited Vulnerabilities catalog on April 21, 2023, mandating federal agencies patch by May 12. VulnCheck subsequently documented a new exploitation method that bypassed existing detections, highlighting the difficulty of detection-only defenses. PaperCut is used by over 100 million users at 70,000+ organizations including large enterprises, government bodies, and educational institutions globally. Patched versions are 20.1.7, 21.2.11, and 22.0.9 and later.
read more about Iranian APTs Exploit PaperCut Vulnerability in Global Cyber Attacks