Latest Update27/08/2026

Threats Feed

  1. Public

    Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft

    In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.

    read more about Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft
  2. Public

    False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand

    In early 2026, the Iranian state-sponsored APT MuddyWater executed a sophisticated false-flag operation masquerading as a Chaos ransomware attack. Primarily targeting the United States, Israel, and MENA organizations—specifically within the construction, manufacturing, and business services sectors—the group bypassed traditional encryption. Instead, they focused on data exfiltration and long-term espionage. Initial access was achieved via Microsoft Teams social engineering, enabling interactive credential harvesting and MFA manipulation. Attackers established persistence using legitimate remote access tools like DWAgent alongside a custom trojanized WebView2 RAT. Analysis of C2 infrastructure and an MOIS-linked code-signing certificate confirmed the attribution. This hybrid intrusion highlights how state actors increasingly leverage cybercriminal RaaS branding to obscure intelligence-gathering operations.

    read more about False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand
  3. Public

    DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities

    DinDoor, a modular Tsundere botnet variant linked to state-sponsored actors like MuddyWater and cybercrime clusters, exploits the Deno runtime to execute obfuscated JavaScript, effectively bypassing traditional endpoint detections. Delivered via deceptive MSI files, recent campaigns have targeted U.S. organizations and the Russian financial services sector. Upon execution, the malware binds a local port as a mutex, aggressively fingerprints the victim’s hardware, and communicates with a multi-tenant command and control (C2) infrastructure, notably serialmenot[.]com. By analyzing unique Caddy proxy HTTP response headers, researchers identified 20 active C2 servers. Ultimately, DinDoor demonstrates how threat actors increasingly abuse trusted, signed runtimes and shared backend platforms to conceal their operations.

    read more about DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities
  4. Public

    MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization

    Oasis Security analyzed a multi-stage campaign attributed with medium-to-high confidence to MuddyWater, targeting critical infrastructure organizations across the Middle East — primarily Egypt, Israel, and the UAE — as well as Portugal and India. The operation began with large-scale automated reconnaissance, scanning more than 12,000 internet-exposed systems for five newly disclosed vulnerabilities affecting web applications, email servers, IT management platforms, and workflow automation tools. Following this broad scanning phase, the actor shifted to selective, high-value targeting: brute-forcing Outlook Web Access (OWA) credentials using custom tooling and multi-threaded frameworks such as Patator, with confirmed credential harvesting against organizations in Egypt, Israel, and the UAE. A modular, multi-protocol command-and-control (C2) infrastructure hosted in the Netherlands was used to manage compromised hosts, leveraging TCP, UDP, and HTTP channels with AES-encrypted communications — patterns consistent with the ArenaC2 framework previously associated with MuddyWater. The campaign resulted in confirmed exfiltration of sensitive data from an Egyptian aviation organization, including passport and visa records, payroll data, credit card information, and internal corporate documents. Approximately 200 files were staged in attacker-controlled directories prior to exfiltration, indicating structured data collection. The operation's timing — beginning in early February 2026, ahead of escalating regional tensions — suggests alignment with broader Iranian strategic intelligence objectives.

    read more about MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization
  5. Public

    MuddyWater's Operation Olalampo: Uncovering C2 Infrastructure and Telegram Bot Utilization in MENA Targets

    The APT group MuddyWater recently launched "Operation Olalampo," targeting organizations and individuals primarily across the MENA region amidst ongoing geopolitical tensions. In this campaign, the threat actors deployed newly developed malware variants and utilized Telegram bots for Command and Control (C&C) operations. A deep dive into the campaign's infrastructure revealed the use of recently registered, Namecheap-administered domains localized in Iceland, routing through US-geolocated IP addresses. Further DNS and threat intelligence analysis uncovered a vast network of over 2,500 connected domains linked to a single registrant email, along with active communications originating from ten potential victim IP addresses.

    read more about MuddyWater's Operation Olalampo: Uncovering C2 Infrastructure and Telegram Bot Utilization in MENA Targets
  6. Public

    MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage

    Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.

    read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
  7. Public

    HTTP_VIP Malware Profile: System Reconnaissance and RMM Payload Delivery

    HTTP_VIP is a downloader malware attributed to the Iranian state-aligned threat actor MuddyWater. Analyzed during the early-2026 campaign dubbed "Operation Olalampo," this tool functions primarily to establish a foothold on compromised systems. It executes system reconnaissance while employing virtualization and sandbox evasion techniques to bypass defensive analysis. Following successful execution, HTTP_VIP connects to its command and control infrastructure to retrieve secondary payloads. Notably, the threat actors utilize this downloader to deploy legitimate remote monitoring and management (RMM) software, specifically AnyDesk. The deployment of AnyDesk facilitates persistent remote access and control over the victim environments, blending malicious activity with standard administrative tools.

    read more about HTTP_VIP Malware Profile: System Reconnaissance and RMM Payload Delivery
  8. Public

    MuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs

    Huntress researchers have detailed a complete attack chain attributed to the Iranian-linked APT MuddyWater, targeting an Israeli company. The intrusion began with initial access via an RDP login, followed by extensive interactive network and Active Directory reconnaissance. The threat actor demonstrated hands-on-keyboard activity, evidenced by typographical errors during command execution. To establish persistent access and bypass network controls, the attackers utilized the native Windows OpenSSH client to create reverse SSH tunnels. Subsequently, they deployed a malicious payload via DLL side-loading, leveraging the legitimate Fortemedia application (FMAPP.exe) to execute a malicious DLL (FMAPP.dll) for command-and-control communications.

    read more about MuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs
  9. Public

    Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors

    The Iranian APT group Seedworm has targeted multiple organizations across the U.S., Canada, and Israel since February 2026. Leveraging custom malware, the threat actors compromised networks within the financial, aviation, software, defense, and non-profit sectors. Attackers deployed a novel JavaScript/TypeScript backdoor named Dindoor, alongside a Python-based backdoor called Fakeset. To evade detection, the group signed their payloads with digital certificates issued to "Amy Cherne" and "Donald Gay." Additionally, the attackers utilized legitimate cloud services, including Backblaze for staging and Rclone for attempted data exfiltration to Wasabi buckets. Given Seedworm’s affiliation with the Iranian Ministry of Intelligence and Security, these intrusions pose a significant espionage threat amidst current geopolitical conflicts.

    read more about Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors
  10. Public

    Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure

    Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.

    read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
  11. Public

    MuddyWater APT's Evolving Tactics: From Macros to RMM Tool Abuse

    MuddyWater APT has conducted sustained cyberespionage campaigns across the Middle East and globally, targeting telecommunications, education, insurance, IT services, and diplomatic sectors. Affected countries include Iraq, Jordan, Egypt, Israel, Malaysia, Oman, and Turkmenistan. The threat actor’s tactics have evolved significantly, shifting from traditional spear-phishing with macro-enabled Microsoft Word documents to deploying malicious HTML files and encrypted archives. Notably, the group increasingly abuses legitimate Remote Monitoring and Management (RMM) tools, such as Syncro and Atera, as initial access vectors. By distributing properly signed installer files disguised as official communications, MuddyWater successfully evades security detection, establishing persistent, stealthy footholds for long-term intelligence collection without relying on custom malware.

    read more about MuddyWater APT's Evolving Tactics: From Macros to RMM Tool Abuse
  12. Public

    Operation Olalampo: MuddyWater Deploys AI-Assisted Malware in MENA Region Attacks

    Operation Olalampo is a new cyber campaign by the Iranian threat group MuddyWater, targeting organizations primarily across the MENA region. Aligning with ongoing geopolitical tensions, the attacks focus on energy and marine services, system integrators, and specific individuals of interest. The adversary gains initial access by exploiting vulnerabilities on public-facing servers and distributing macro-enabled phishing documents. This campaign introduces four novel malware variants: GhostFetch, HTTP_VIP, GhostBackDoor, and a Rust-based backdoor named CHAR. Notably, CHAR leverages a Telegram bot for command-and-control and exhibits evidence of AI-assisted development. Post-exploitation activities include local reconnaissance, credential theft, and the deployment of legitimate tools like AnyDesk. Infrastructure analysis also reveals overlap with MuddyWater’s historical operations from late 2025.

    read more about Operation Olalampo: MuddyWater Deploys AI-Assisted Malware in MENA Region Attacks
  13. Public

    RustyStealer’s Evolution: Tracking MuddyWater’s Rust Implant from Experimentation to Stealth

    The report analyzes the evolution of RustyStealer (also referenced as RustyWater or Archer RAT), a Rust-based post-compromise implant observed in MuddyWater-attributed activity. By correlating build artefacts, compiler metadata, dependency drift, TLSH similarity, and API-level changes, the analysis reconstructs a development timeline from early baseline builds to a more mature v2.0 architecture. Rather than linear feature growth, the samples reveal experimentation, rollback, and consolidation. A short-lived asynchronous I/O refactor was abandoned in favor of improved stability, while later versions emphasize stealth through native NT API usage, runtime string obfuscation, and restored host fingerprinting.

    read more about RustyStealer’s Evolution: Tracking MuddyWater’s Rust Implant from Experimentation to Stealth
  14. Public

    MuddyWater Malware Exposes Developer Build Artifacts Through Poor OPSEC

    The report analyzes a newly observed MuddyWater malware sample that exposes extensive build and development artifacts due to improper binary stripping. Delivered via a malicious Word document containing VBA macros, the payload reconstructs and executes a Rust-based executable on disk. Analysis of leftover strings reveals detailed insights into the actor’s development environment, including a Windows-based build host, MSVC Rust toolchain, local Cargo usage, and a recurring username embedded in build paths. These artifacts indicate locally compiled tooling with minimal release hardening and weak OPSEC. The findings highlight how developer mistakes can provide durable fingerprints for clustering, campaign tracking, and long-term threat hunting, beyond traditional infrastructure indicators.

    read more about MuddyWater Malware Exposes Developer Build Artifacts Through Poor OPSEC
  15. Public

    MuddyWater Adopts Rust-Based RustyWater Implant in Middle East Espionage Campaign

    CloudSEK identified a spearphishing campaign attributed to the MuddyWater APT group targeting diplomatic, maritime, financial, telecom, education, and shipping sectors across the Middle East, including Turkmenistan, the UAE, and regional maritime organizations. The operation uses impersonated government and telecom emails to deliver malicious Word documents embedding obfuscated VBA macros. These macros drop and execute a Rust-based implant dubbed RustyWater, which provides asynchronous HTTP C2, registry persistence, anti-analysis features, and modular post-compromise capabilities. The shift from PowerShell and VBS loaders to a Rust RAT marks a significant evolution in MuddyWater’s tooling toward stealthier, long-term espionage operations.

    read more about MuddyWater Adopts Rust-Based RustyWater Implant in Middle East Espionage Campaign
  16. Public

    MuddyWater Deploys UDPGangster Backdoor in Regional Espionage Campaigns

    UDPGangster is a UDP-based backdoor used in recent MuddyWater cyber espionage campaigns targeting Turkey, Israel, and Azerbaijan. The attacks rely on phishing emails delivering malicious macro-enabled Word documents that decode and execute the payload. Once installed, the malware establishes persistence, performs extensive anti-analysis and sandbox evasion checks, and communicates with its C2 over non-standard UDP channels to execute commands, exfiltrate files, and deploy additional payloads. Related samples and shared infrastructure, including overlap with the Phoenix backdoor, confirm MuddyWater attribution across these regionally focused intrusions.

    read more about MuddyWater Deploys UDPGangster Backdoor in Regional Espionage Campaigns
  17. Public

    MuddyWater Targets Israeli Organizations with Custom BlackBeard Backdoor

    The Iranian threat group MuddyWater recently launched highly targeted phishing campaigns against Israeli organizations, utilizing compromised corporate email accounts to distribute malicious macro-enabled Word documents. The attacks rely on localized social engineering, featuring tailored Hebrew content, legitimate branding, and lookalike domains. Upon execution, the campaign deploys "BlackBeard," a custom Rust-based backdoor capable of EDR evasion, system reconnaissance, and downloading additional payloads via encrypted HTTPS channels. Persistence is achieved through stealthy file association hijacking. The threat actors then leverage the newly compromised accounts to conduct internal spearphishing, enabling rapid lateral movement. This campaign demonstrates MuddyWater's persistent cyber espionage efforts and sophisticated tactical adaptations.

    read more about MuddyWater Targets Israeli Organizations with Custom BlackBeard Backdoor
  18. Public

    MuddyWater Deploys New Toolset in Targeted Attacks on Israel and Egypt

    ESET researchers uncovered a new MuddyWater campaign targeting organizations in Israel and one in Egypt, primarily within the telecommunications, government, oil and energy, and manufacturing sectors. The Iran-aligned group deployed a suite of newly developed tools, including the Fooder reflective loader and MuddyViper, a C/C++ backdoor capable of credential theft, system reconnaissance, and file operations. Additional stealers such as CE-Notes, LP-Notes, and Blub, along with customized go-socks5 reverse tunnels, enhanced persistence and defense evasion. The campaign also revealed operational overlap with Lyceum, indicating MuddyWater’s role as an initial access broker. Activity ran from September 30, 2024 to March 18, 2025.

    read more about MuddyWater Deploys New Toolset in Targeted Attacks on Israel and Egypt
  19. Public

    MuddyWater Unveils New Espionage Toolkit in Global Phishing Campaign

    Group-IB uncovered a global phishing campaign by the Iran-linked APT MuddyWater, targeting international and humanitarian organizations across the Middle East, Europe, Africa, and North America. The group used a compromised mailbox accessed via NordVPN to send phishing emails with malicious Word documents containing VBA macros that deployed the Phoenix backdoor v4 through the FakeUpdate injector. The malware achieved persistence via Winlogon registry keys and COM hijacking, while a custom browser credential stealer and RMM tools (PDQ, Action1) facilitated remote access and credential harvesting. The campaign reflects MuddyWater’s evolving espionage capabilities and integration of custom and legitimate tools for stealth operations.

    read more about MuddyWater Unveils New Espionage Toolkit in Global Phishing Campaign
  20. Public

    MuddyWater Targets CFOs Worldwide with Multi-Stage Phishing and NetBird Abuse

    APT MuddyWater has launched a multi-stage spear-phishing campaign targeting CFOs and finance executives across Europe, North America, South America, Africa, and Asia. Disguised as recruiters from Rothschild & Co, the attackers use Firebase-hosted phishing pages with CAPTCHA lures and malicious ZIP/VBS payloads to deploy legitimate remote-access tools like NetBird and OpenSSH for persistent control. The infection chain creates hidden admin accounts, enables RDP, and automates persistence via scheduled tasks. Infrastructure analysis reveals overlaps with earlier MuddyWater operations, confirming attribution and highlighting the group’s evolving phishing toolkit and adaptive use of trusted cloud services for global financial espionage.

    read more about MuddyWater Targets CFOs Worldwide with Multi-Stage Phishing and NetBird Abuse
  21. Public

    MuddyWater Deploys New Android Spyware Amid Israel-Iran Conflict

    Iranian APT group MuddyWater deployed new versions of its Android surveillanceware DCHSpy amid the Israel-Iran conflict, targeting individuals via politically themed lures such as fake Starlink VPN apps. Distributed through Telegram and disguised as legitimate VPN or banking apps, DCHSpy harvests sensitive data including WhatsApp messages, SMS, call logs, contacts, device location, and audio. The malware compresses and encrypts exfiltrated data before uploading it to an attacker-controlled SFTP server. DCHSpy shares infrastructure with SandStrike, a tool previously used to target Baháʼí practitioners. Sectors targeted include telecommunications, defense, local government, and oil and gas across the Middle East, Asia, Africa, Europe, and North America.

    read more about MuddyWater Deploys New Android Spyware Amid Israel-Iran Conflict
  22. Public

    Avast-Themed Phishing Campaign Targets Israeli Businesses with ScreenConnect RAT

    A phishing campaign impersonating Avast targeted Israeli individuals and businesses—likely in the real estate and commercial sectors—through fraudulent antivirus receipts containing malware download links. The attack used multiple URL redirections and GitHub for payload delivery, culminating in the stealthy installation of the legitimate remote access tool ScreenConnect. Once installed, the malware achieved persistence via Windows services, modified authentication packages to access credentials, and established encrypted command and control connections. Evidence suggests similarities with tactics used by the MuddyWater APT group, though attribution remains inconclusive. The campaign’s infrastructure and system language checks confirm its Israeli focus.

    read more about Avast-Themed Phishing Campaign Targets Israeli Businesses with ScreenConnect RAT
  23. Public

    MuddyWater Deploys Macro-Enabled Documents to Deliver VBScript Backdoor

    The MuddyWater APT group has been observed using malicious macro-enabled Microsoft Word documents to compromise targets. Upon opening these documents and enabling macros, a VBScript backdoor is deployed, establishing communication with attacker-controlled command and control (C2) servers via HTTP. The VBScript backdoor receives and executes remote commands and sends results back to the C2 servers. Identified infrastructure includes domains and IP addresses employing HTTPS over port 443 for covert communication, aiding in firewall evasion.

    read more about MuddyWater Deploys Macro-Enabled Documents to Deliver VBScript Backdoor
  24. Public

    MuddyWater Expands Custom Tooling and Phishing Operations Targeting Israel in 2024

    In 2024, the Iranian-linked threat group MuddyWater significantly advanced its operational capabilities, conducting large-scale spear-phishing and broad phishing campaigns worldwide with a strong focus on Israel and the Middle East. The group abused legitimate file-sharing platforms and remote management tools to gain initial access, while increasingly deploying custom-developed malware such as BugSleep, Blackout, AnchorRat, CannonRat, and BlackPearl. Operations leveraged persistence mechanisms including COM hijacking, DLL side-loading, registry modifications, and Windows services. MuddyWater relied on encrypted HTTP, DNS, and SOCKS5-based C2 channels, targeting aviation, healthcare, telecommunications, IT, and small and medium-sized businesses for long-term intelligence collection.

    read more about MuddyWater Expands Custom Tooling and Phishing Operations Targeting Israel in 2024