Threats Feed|Seedworm|Last Updated 28/05/2026|AuthorCertfa Radar|Publish Date28/02/2019

SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants

  • Actor Motivations: Exfiltration
  • Attack Vectors: Backdoor,Downloader,Malware
  • Attack Complexity: Medium
  • Threat Risk: Unknown

Threat Overview

The provided report outlines the activities of a malware campaign leveraging the SeedWorm backdoor, specifically through variants of a program named LisfonService. These variants were developed and deployed using PowerShell to download and execute a malicious program, 'muddy', across targeted systems. Notably, the campaign utilizes filenames such as svchosts.exe and lisfon.exe to obscure its malicious intent.

Extracted IOCs

  • 51ac160f7d60a9ce642080af0425a446fb25b7067e06b3a9a8ec2f777836efd3
  • 5723f425e0c55c22c6b8bb74afb6b506943012c33b9ec1c928a71307a8c5889a
  • 58972b27b7dc40494e715c2f39a1bcee4d8c18da6bcc3e22785496cca2cee1a0
  • 6f8226d890350943a9ef4cc81598e0e953d8ba9746694c0b7e3d99e418701b39
  • 9262bf6be648e1b15850a776fe4e393250d74afdf911e94ae07718f8ad4d1664
  • bf696397784b22f8e891dd0627dce731f288d14d4791ac5d0a906bc1cbe10de6
  • c514c3f293f0cb4c23662a5ab962b158cb97580b03a22b82e21fa3b26d64809c
  • f1f11830b60e6530b680291509ddd9b5a1e5f425550444ec964a08f5f0c1a44e
  • 31[.]171.154.67
  • 46[.]99.148.96
  • 78[.]129.139.148
  • 78[.]129.222.56
  • 79[.]106.224.203
download

Tip: 13 related IOCs (5 IP, 0 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater APT: Iran's Cyber Espionage Across the Middle East and Beyond

Source: SOCRadar - January 2023

Detection (two cases): 6f8226d890350943a9ef4cc81598e0e953d8ba9746694c0b7e3d99e418701b39, c514c3f293f0cb4c23662a5ab962b158cb97580b03a22b82e21fa3b26d64809c

MuddyWaterMuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics

Source: Picussecurity - March 2022

Detection (four cases): 51ac160f7d60a9ce642080af0425a446fb25b7067e06b3a9a8ec2f777836efd3, 5723f425e0c55c22c6b8bb74afb6b506943012c33b9ec1c928a71307a8c5889a, bf696397784b22f8e891dd0627dce731f288d14d4791ac5d0a906bc1cbe10de6, f1f11830b60e6530b680291509ddd9b5a1e5f425550444ec964a08f5f0c1a44e

MuddyWaterMuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

Source: Trend Micro - June 2019

Detection (four cases): 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 79[.]106.224.203

MuddyWaterDecoding MuddyWater: Inside the APT's Advanced Toolset and Deception Tactics

Source: Kaspersky - April 2019

Detection (one case): 78[.]129.222.56

SeedwormSeedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors

Source: Symantec - December 2018

Detection (five cases): 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 78[.]129.222.56, 79[.]106.224.203

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

SeedWorm Malware Campaign

A malware campaign known as "SeedWorm" has been detected targeting computer systems. Attackers are using a backdoor program called "LisfonService" alongside system scripts to infect computers.

The alert identifies the activity as part of the SeedWorm campaign.

The primary goal is to infect systems with a backdoor, granting the attackers unauthorized, hidden access. Once inside, they use techniques to avoid detection, communicate with their own servers, and potentially steal sensitive data.

Organizations must keep their software and antivirus programs updated, block the specific internet addresses associated with the attack, and limit users' ability to install unapproved software. Individuals should be highly cautious when opening email attachments and should avoid downloading files from untrusted websites.

The report classifies the severity of the threat as "Medium."

About Affiliation
Seedworm
Seedworm is Symantec's designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Active since at least 2017, Symantec documented the group's targeting of government, energy, and telecommunications organizations across the Middle East and Central Asia. Seedworm operations use spear phishing to deliver custom backdoors including POWERSTATS and Canopy, with Symantec noting the group's rapid operational tempo — often pivoting from initial compromise to active data collection within hours. The cluster shares infrastructure, tooling, and targeting patterns with MuddyWater tracking across other vendors.
View Seedworm's Insights