MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Brute-force,Vulnerability Exploitation,Backdoor
- Attack Complexity: High
- Threat Risk: High Impact/High Probability
Threat Overview
Oasis Security analyzed a multi-stage campaign attributed with medium-to-high confidence to MuddyWater, targeting critical infrastructure organizations across the Middle East — primarily Egypt, Israel, and the UAE — as well as Portugal and India. The operation began with large-scale automated reconnaissance, scanning more than 12,000 internet-exposed systems for five newly disclosed vulnerabilities affecting web applications, email servers, IT management platforms, and workflow automation tools. Following this broad scanning phase, the actor shifted to selective, high-value targeting: brute-forcing Outlook Web Access (OWA) credentials using custom tooling and multi-threaded frameworks such as Patator, with confirmed credential harvesting against organizations in Egypt, Israel, and the UAE. A modular, multi-protocol command-and-control (C2) infrastructure hosted in the Netherlands was used to manage compromised hosts, leveraging TCP, UDP, and HTTP channels with AES-encrypted communications — patterns consistent with the ArenaC2 framework previously associated with MuddyWater. The campaign resulted in confirmed exfiltration of sensitive data from an Egyptian aviation organization, including passport and visa records, payroll data, credit card information, and internal corporate documents. Approximately 200 files were staged in attacker-controlled directories prior to exfiltration, indicating structured data collection. The operation's timing — beginning in early February 2026, ahead of escalating regional tensions — suggests alignment with broader Iranian strategic intelligence objectives.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Government Agencies and Services Government and public sector entities explicitly named as primary targets across Middle Eastern countries. | Verified |
| Sector | Energy Energy and infrastructure companies explicitly listed as targeted sectors in the campaign. | High |
| Sector | Transportation Aviation organizations in Egypt explicitly named as targets; data exfiltrated from an Egyptian aviation entity. | Verified |
| Region | Egypt | Verified |
| Region | India | Verified |
| Region | Israel | Verified |
| Region | Portugal | Verified |
| Region | United Arab Emirates | Verified |
Extracted IOCs
- 157[.]20.182.49
Tip: 1 related IOCs (1 IP, 0 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: JUMPSEC - April 2026
Detection (one case): 157[.]20.182.49
Source: Huntress - March 2026
Detection (one case): 157[.]20.182.49
Source: Hunt.io - March 2026
Detection (one case): 157[.]20.182.49
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions
Researchers at Oasis Security identified a multi-stage cyberattack campaign starting in early February 2026. The attackers scanned more than 12,000 internet-facing systems for known vulnerabilities, then shifted to targeted credential theft and data theft against organizations in Egypt, Israel, the UAE, Portugal, and India. The campaign ultimately resulted in confirmed data being stolen from an aviation company in Egypt.
The campaign is attributed with medium-to-high confidence to MuddyWater, an Iranian state-linked threat group active since at least 2017. The attribution is based on the attack's command-and-control infrastructure sharing characteristics with the ArenaC2 framework previously associated with MuddyWater, as well as consistent multi-protocol communication patterns documented in prior MuddyWater operations.
The primary goals were intelligence collection and data theft. The attackers focused on stealing sensitive records — including passport and visa documents, payroll data, financial information, and internal corporate files — from high-value targets in the aviation, energy, and government sectors. The campaign's timing, beginning just ahead of escalating regional tensions in the Middle East, suggests it was aligned with Iranian strategic intelligence priorities.
The reconnaissance phase was wide — more than 12,000 internet-exposed systems were scanned globally. However, targeted intrusion attempts were regionally focused on the Middle East, specifically Egypt, Israel, and the UAE, with additional activity identified in Portugal and India. The confirmed data theft was limited to a single Egyptian aviation organization, though credential harvesting attempts were made against multiple organizations across these countries.
The campaign specifically targeted organizations in aviation, energy, and government — sectors with high operational and geopolitical significance. Confirmed victims and credential harvesting attempts were focused on entities in Egypt, Israel, and the UAE. An Egyptian aviation company suffered confirmed data theft. Government bodies and energy-sector organizations across the region were also targeted, reflecting the actor's interest in operationally sensitive infrastructure.
The attackers used a three-phase approach. First, they ran automated scans against more than 12,000 systems to identify those vulnerable to five newly disclosed software flaws. Second, they used custom scripts and tools to guess passwords on corporate email login pages (Outlook Web Access), gaining access to employee accounts. Finally, they installed modular command-and-control software on compromised systems, collected sensitive files, and transferred them to attacker-controlled servers hosted in the Netherlands — all while encrypting their communications to avoid detection.
Aviation, energy, and government organizations are priority targets for state-linked threat actors because they hold sensitive operational data, handle critical infrastructure, and carry significant geopolitical weight. For Iran-linked groups in particular, these sectors provide intelligence about regional military logistics, energy supply chains, and government operations — all of which have direct strategic value, especially during periods of heightened regional tension.
Organizations should immediately apply patches for CVE-2025-54068, CVE-2025-52691, CVE-2025-68613, CVE-2025-9316, and CVE-2025-34291. Multi-factor authentication should be enforced on all externally accessible services, especially Outlook Web Access and remote management tools. Security teams should monitor for repeated failed login attempts and unusual authentication patterns, block traffic from the known attacker IP (157.20.182[.]49), and inspect network logs for encrypted communications over non-standard ports. Any bulk file access or data staging activity on internal systems should be investigated promptly.