MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Downloader,Dropper,Keylogger,Malicious Macro,Malware,RAT,Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Aerospace | Verified |
| Sector | Energy | Verified |
| Region | Israel | Verified |
| Region | United States | Verified |
Exploited Vulnerabilities
Extracted IOCs
- mazafakaerindahouse[.]info
- serialmenot[.]com
- sharecodepro[.]com
- ttrdomennew[.]com
- 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90
- 49f17c061a72cadaf9e3f90cc380e994883a965b7a4ad8953d8e8089c65908e6
- 4aaf77c410f1f465d5e9063af60a07ad184e7a92ee87c973c2ea1542bfd66bff
- 7ab597ff0b1a5e6916cad1662b49f58231867a1d4fa91a4edf7ecb73c3ec7fe6
- 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444
- a8c380b57cb7c381ca6ba845bd7af7333f52ee4dc4e935e98b48bb81facad72b
- a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
- bedb882c6e2cf896e14ecf12c90aaa6638f780017d1b8687a40b4a81956e230f
- c8589ca999526f247db4d3902ade8a85619f8f82338c6230d1b935f413ddcb3d
- d91f7a2962c0e9de3cd4ea9c770092d86b1641e89f0a7be2307b6451f00e5271
- 157[.]20.182.49
- 172[.]86.123.222
- 23[.]94.145.120
Tip: 17 related IOCs (3 IP, 4 domain, 0 URL, 0 email, 10 file hash) to this threat have been found.
Overlaps
Source: Rapid7 - May 2026
Detection (two cases): 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
Source: Oasis Security - April 2026
Detection (one case): 157[.]20.182.49
Source: Check Point - March 2026
Detection (three cases): 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444, a8c380b57cb7c381ca6ba845bd7af7333f52ee4dc4e935e98b48bb81facad72b, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
Source: Huntress - March 2026
Detection (one case): 157[.]20.182.49
Source: Symantec - March 2026
Detection (four cases): 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90, 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0, serialmenot[.]com
Source: Hunt.io - March 2026
Detection (one case): 157[.]20.182.49
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Demystifying the MuddyWater and CastleRAT Cyber Threat
An Iranian state-sponsored cyber espionage group was discovered using malicious software purchased from Russian cybercriminals. Instead of building their own hacking tools, the group bought an off-the-shelf system to upgrade their capabilities. This allowed them to launch sophisticated attacks while blending in with standard criminal activity.
The attacks were carried out by MuddyWater, a well-known cyber espionage group linked to Iran's Ministry of Intelligence and Security (MOIS). The tools they purchased and deployed belong to TAG-150, a Russian-speaking group that rents out its malware to other hackers.
The primary goal of this campaign is state-level espionage and data theft. By utilizing commercial malware, the attackers upgraded their ability to steal credentials, bypass modern security protections, and silently control compromised computers without the users noticing.
These campaigns remain highly active and operational. The attackers have continually updated their tools and launched new attacks throughout early 2026, maintaining a steady pace of operations even after their initial infrastructure was exposed by security researchers.
Yes. The attackers focused heavily on Israeli networks, specific web applications, and network security appliances. They have also actively targeted the United States aerospace sector, including sending highly specific phishing emails to an aerospace parts distributor.
The attackers tricked victims into opening deceptive files, such as malicious documents delivered via email. Once opened, these files silently installed hidden software that uses complex blockchain technology to securely communicate with the attackers' servers. The attackers could then secretly view the victim's screen and steal sensitive data.
Organizations in defense, aerospace, energy, and government sectors possess highly valuable intellectual property and national security secrets. Espionage groups target these entities to gain a geopolitical, military, or technological advantage for their host nation.
Organizations should strengthen their email security to intercept advanced phishing attempts and train staff to recognize industry-specific deceptive messages. Security teams must also update their monitoring tools to look for this specific blend of criminal malware being used for espionage, rather than writing it off as a standard virus.
This is a highly targeted threat aimed at specific geopolitical adversaries and high-value sectors, rather than a widespread attack on the general public. However, any organization within the defense, aerospace, energy, or government sectors should be on high alert.