Threats Feed
- Public
MuddyWater Expands Cyberattacks with Two-Stage Spear-phishing Campaign Targeting Lebanon and Oman
The MuddyWater threat group has been launching two-stage spear-phishing attacks on targets in Lebanon and Oman. The first stage involves sending macro-embedded documents posing as resumes or official letters. These documents contain obfuscated code hosted on compromised domains. In the second stage, obfuscated source code from these domains is executed to propagate MuddyWater's main PowerShell backdoor, POWERSTATS. This campaign marks a shift from single-stage to two-stage attacks, allowing for stealthier delivery of the payload.
read more about MuddyWater Expands Cyberattacks with Two-Stage Spear-phishing Campaign Targeting Lebanon and Oman - Public
MuddyWater APT's Spear Phishing Campaigns Target Middle East's Sectors
The MuddyWater APT group has been leveraging spear phishing attacks with malicious Word documents to infiltrate systems in the oil, military, telecom, and government sectors. These documents, often in the native language of the target, entice users to enable macros, leading to a chain of malicious activities. The malware, once activated, employs techniques like modifying registry keys, creating scheduled tasks, and using PowerShell to decode payloads and establish persistence. It cleverly evades detection by disguising its activities under seemingly legitimate processes and alters security settings like disabling firewalls and antivirus. Network analysis revealed beaconing to C2 servers, indicating a sophisticated level of stealth and persistence.
read more about MuddyWater APT's Spear Phishing Campaigns Target Middle East's Sectors - Public
MuddyWater Expands Spear-Phishing Operations across Multiple Countries and Sectors
The MuddyWater group has expanded its cyber operations, focusing mainly on government bodies, military entities, telecommunication companies, and educational institutions. The new spear-phishing docs used by MuddyWater rely on social engineering to persuade users to enable macros, thereby initiating malware extraction and execution. The malware is designed for extensive system reconnaissance, and the command-and-control communication structure allows the threat actors to accept or reject victims based on various criteria.
read more about MuddyWater Expands Spear-Phishing Operations across Multiple Countries and Sectors - Public
Evolving MuddyWater Campaign Uncovered with PRB-Backdoor Payload
A potential MuddyWater campaign has been discovered using a new sample found in May 2018. The campaign involves a malicious Microsoft Word document with an embedded macro capable of executing PowerShell scripts, leading to a PRB-Backdoor payload. Notably, the lure document's subject matter has changed from government or telecommunications-related documents to rewards or promotions, suggesting that targets may no longer be limited to specific industries or organizations. The backdoor communicates with a C&C server to perform various functions, such as gathering system information, keylogging, and capturing screenshots.
read more about Evolving MuddyWater Campaign Uncovered with PRB-Backdoor Payload - Public
PRB-Backdoor: MuddyWater's Multifaceted Malware Uncovered
This report investigates the PRB-Backdoor, a powerful and multifunctional piece of malware suspected to be associated with the MuddyWater group. The malware is deployed via a macro-enabled Word document, utilizing PowerShell scripts for execution. It employs obfuscation techniques to conceal its activities and communicates with a command and control server over HTTP. The backdoor has a plethora of functionalities, including keylogging, screen capturing, system information collection, and password theft. The backdoor seems to be new and unique, with no references found in any public source.
read more about PRB-Backdoor: MuddyWater's Multifaceted Malware Uncovered - Public
Cyber Espionage Evolution: MuddyWater’s Obfuscation Techniques and Anti-Analysis Measures
The MuddyWater or Temp.Zagros group has resumed its activities after a perceived quiet phase, with recent samples revealing additional obfuscation layers. The group continues to use PowerShell, targeting regions such as Turkey, Iraq, and Pakistan, with a potential focus on governmental sectors. The recent malicious documents include a new variant of the POWERSTATS backdoor, with anti-analysis and debugging features such as BSOD functionality. They have also included checks for security software and process names to impair defensive measures.
read more about Cyber Espionage Evolution: MuddyWater’s Obfuscation Techniques and Anti-Analysis Measures - Public
Multi-Stage Spear Phishing Attack Traced to Iran: TEMP.Zagros in Action
The Iran-affiliated threat actor, TEMP.Zagros, orchestrated a spear-phishing campaign from January to March 2018, primarily targeting individuals across Turkey, Pakistan, Tajikistan, and India. This actor leveraged malicious macro-based documents with geopolitical themes to install the POWERSTATS backdoor on victims' systems. The campaign exhibited evolving tactics over time, employing both VBS files and INF/SCT files to indirectly execute PowerShell commands. The installed malware demonstrated a range of functionalities, from system data extraction and screenshot capture to checks for security tools and remote command execution.
read more about Multi-Stage Spear Phishing Attack Traced to Iran: TEMP.Zagros in Action - Public
MuddyWater Resurfaces: Cyber Attacks Target Turkey, Pakistan, and Tajikistan
A new cyber-espionage campaign, bearing similarities to the earlier MuddyWater attacks, is targeting government organizations and telecommunication companies in Turkey, Pakistan, and Tajikistan. The campaign uses spear-phishing tactics with malicious documents, leveraging social engineering to trick victims into enabling macros and activating payloads. Visual Basic and PowerShell scripts are used, with obfuscation techniques employed to evade detection. The attackers also use persistence methods and engage in system owner/user discovery, collecting system information and taking screenshots before sending this data to a command-and-control server.
read more about MuddyWater Resurfaces: Cyber Attacks Target Turkey, Pakistan, and Tajikistan - Public
MuddyWater APT Focuses on Espionage in the Middle East: A Technical Analysis
ReaQta's November 2017 report documents MuddyWater, an Iranian-linked APT group active throughout 2017 targeting government, telecom, and oil sector organizations in the Middle East — primarily Iraq, Saudi Arabia, and UAE. The group's primary backdoor, POWERSTATS, is a PowerShell-based in-memory implant that exemplifies "living off the land" tradecraft: it leaves no binary on disk, uses legitimate system tools for execution, and leverages compromised third-party websites as proxy C2 relays to conceal the real C2 server. ReaQta first identified MuddyWater in September 2017 when it discovered an active campaign using GitHub for payload hosting, then observed the group rapidly pivot to Pastebin after GitHub blocked their account, and subsequently embed the payload directly in the macro document. The group shifted C2 servers four times between September and November 2017 in response to public disclosures. Following Saudi Arabia's National Cybersecurity Center advisory in November 2017, MuddyWater added Koadic (a JScript RAT) and Meterpreter as secondary payloads. Key findings include: 10% of endpoints at a major Iraqi telecom provider were infected; 85% of victims ran Windows workstations with the remaining 15% being servers; operators showed high activity on Iraqi, Saudi, and UAE victims while largely ignoring Pakistani infections despite Pakistan having the most raw infections; attack hours were consistent with an Iranian work schedule. IOCs include 7 C2 IPs, 54 domains (compromised proxy sites), 74 C2 URLs, and 17 file hashes.
read more about MuddyWater APT Focuses on Espionage in the Middle East: A Technical Analysis - Public
MuddyWater Targets Middle East Using POWERSTATS Backdoor
The research team at Palo Alto Networks has discovered a group of targeted cyber-attacks against the Middle East region that occurred between February and October 2017, carried out by "MuddyWater". These attacks are espionage-related. The group used a PowerShell-based first-stage backdoor called "POWERSTATS", which evolved slowly over time, and targeted countries including the USA and India, as well as those within the Middle East like Saudi Arabia, Iraq, Israel, and the United Arab Emirates. The group also used GitHub to host its backdoor.
read more about MuddyWater Targets Middle East Using POWERSTATS Backdoor - Public
Continuing MuddyWater Phishing Campaign Targets Middle East and Pakistan
MuddyWater group continues its cyber-espionage operations, leveraging obfuscated PowerShell scripts within Word documents to infiltrate systems. These documents masquerade as legitimate entities, such as the Federal Investigation Agency of Pakistan. The tactics include sophisticated obfuscation techniques and a careful reconnaissance strategy, primarily focusing on the Middle East and Pakistan. The campaign deploys a variety of tools, including C&C servers and proxies, with a detailed focus on avoiding detection by analysis tools.
read more about Continuing MuddyWater Phishing Campaign Targets Middle East and Pakistan - Public
Unveiling MuddyWater Phishing Campaign: Middle Eastern Governments in the Crosshairs
Entities in the Middle East, including Saudi Arabia and Iraq, were targeted by an early MuddyWater phishing campaign predominantly aimed at the government sector. Spear-phishing emails carrying malicious attachments were a key tactic, with PowerShell scripts being sourced from Pastebin and Filebin. To avoid detection, the attackers concealed their scripts. Upon examining the macro code and command and control scripts, parallels were found with a campaign previously discussed by Morphisec.
read more about Unveiling MuddyWater Phishing Campaign: Middle Eastern Governments in the Crosshairs