MuddyWater Masquerades as Hacktivists in Combined Extortion and Disinformation Campaign
- Actor Motivations: Disinformation,Exfiltration,Sabotage
- Attack Vectors: Vulnerability Exploitation,Ransomware,RAT,Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
Iranian state-sponsored threat actor MuddyWater has aggressively targeted Israeli organizations in the finance, academia, and government sectors since late 2022. Operating under the guise of a hacktivist persona named "Darkbit," the group conducted a combined destructive ransomware and disinformation campaign against an academic institution in February 2023. Gaining access via phishing and exploiting vulnerabilities like Log4j, the attackers deployed custom Go-based ransomware alongside remote access tools like SyncroRAT and PowerShower. The operation involved both computer network exploitation, stealing 4TB of data—and computer network attacks, disrupting critical systems while demanding an exorbitant 80 Bitcoin ransom to mask their state-backed espionage and psychological objectives.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Technion Institute The Technion – Israel Institute of Technology is a public research university located in Haifa, Israel. It was established in 1912 and is the oldest university in the country. Technion Institute has been targeted by MuddyWater as the main target. | Verified |
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | University | Verified |
| Region | Israel | Verified |
Extracted IOCs
- 9880fae6551d1e9ee921f39751a6f3c0
- 30466ccd4ec7bcafb370510855da2cd631f74b7a
- 9107be160f7b639d68fe3670de58ed254d81de6aec9a41ad58d91aa814a247ff
Tip: 3 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 3 file hash) to this threat have been found.
Overlaps
Source: Microsoft - April 2023
Detection (one case): 9107be160f7b639d68fe3670de58ed254d81de6aec9a41ad58d91aa814a247ff
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The Darkbit Cyber Attack
A sophisticated cyber attack targeted organizations in Israel, resulting in the theft of sensitive data and the locking of critical computer systems. After disabling the systems, the attackers demanded an exceptionally high ransom to restore access. However, evidence suggests the primary goal was spreading political messages and causing operational disruption rather than collecting money.
The attack was carried out by MuddyWater, a state-sponsored hacking team directed by the Iranian government. To hide their true identity, the attackers operated under the fake name "Darkbit," pretending to be an independent group of politically motivated activists.
This incident combined a destructive computer lock-out with a political influence campaign. While the attackers demanded a massive financial payout, their true intentions were to disrupt business operations, steal data, and spread anti-Israeli propaganda under the guise of hacktivism.
The attack was highly disruptive, with the perpetrators claiming to have stolen four terabytes of organizational data. Following the data theft, they successfully locked numerous servers and individual workstations, causing major interruptions to business-critical systems.
Yes, the attackers specifically focused their efforts on the academic, financial, and government sectors within Israel. Technical evidence reveals that a major academic institution was a direct, pre-planned target, as the attackers had mapped out its specific computer network in advance.
The attackers initially broke into the networks using deceptive emails and by taking advantage of known software weaknesses that had not been properly updated. Once inside, they stole large amounts of data and launched a custom-built program that locked computer files while intentionally deleting system backups to prevent easy recovery.
Institutions in the academic, financial, and government sectors hold vast amounts of sensitive information, intellectual property, and critical operational data. Disrupting these high-profile organizations allows state-sponsored attackers to cause significant economic impact while maximizing the public visibility of their political messages.
Organizations should immediately apply software updates to fix known weaknesses, particularly those that attackers are actively exploiting to break into systems. It is also crucial to train staff to recognize deceptive emails and to monitor computer networks closely for any programs attempting to delete system backups.
This was a highly targeted and calculated operation rather than a random, widespread internet attack. The attackers specifically customized their malicious software and planned their intrusion to strike a pre-selected list of computers belonging to the targeted institution.