Threats Feed|MuddyWater|Last Updated 28/01/2026|AuthorCertfa Radar|Publish Date04/12/2025

MuddyWater Deploys UDPGangster Backdoor in Regional Espionage Campaigns

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Dropper,Malicious Macro,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

UDPGangster is a UDP-based backdoor used in recent MuddyWater cyber espionage campaigns targeting Turkey, Israel, and Azerbaijan. The attacks rely on phishing emails delivering malicious macro-enabled Word documents that decode and execute the payload. Once installed, the malware establishes persistence, performs extensive anti-analysis and sandbox evasion checks, and communicates with its C2 over non-standard UDP channels to execute commands, exfiltrate files, and deploy additional payloads. Related samples and shared infrastructure, including overlap with the Phoenix backdoor, confirm MuddyWater attribution across these regionally focused intrusions.

Detected Targets

TypeDescriptionConfidence
RegionAzerbaijan
Verified
RegionIsrael
Verified
RegionTurkey
Verified

Extracted IOCs

  • reminders.trahum[.]org
  • 01b1073cb0480af3bde735f559898774e1a563e06f9fe56ec3845ea960da0f3c
  • 13d36f3011ed372ad4ec4ace41a6dee52361f221161192cb49c08974c86d160e
  • 232e979493da5329012022d3121300a4b00f813d5b0ecc98fdc3278d8f4e5a48
  • 3d3fbd586f61043ff04ab0369b913a161c0159425fb269d52b7d8d8a14838ece
  • 44deab99e22340fc654494cc4af2b2c27ef1942c6fea6eace9fb94ce7855c0ca
  • 7ea4b307e84c8b32c0220eca13155a4cf66617241f96b8af26ce2db8115e3d53
  • b552e1ca3482ad4b37b1a50717ac577e1961d0be368b49fa1e4e462761ae6eeb
  • b7276cad88103bdb3666025cf9e206b9fb3e66a6d934b66923150d7f23573b60
  • bca7d23b072a2799d124977fdb8384325b30bb1d731741d84a1dfc5e3cf6ac26
  • d177cf65a17bffcd152c5397600950fc0f81f00990ab8a43d352f9a7238428a1
  • e84a5878ea14aa7e2c39d04ea7259d7a4ed7f666c67453a93b28358ccce57bc5
  • fc4a7eed5cb18c52265622ac39a5cef31eec101c898b4016874458d2722ec430
  • 157[.]20.182.75
  • 64[.]7.198.12
  • hxxps://reminders.trahum[.]org/scheduled_internet_outages.doc
download

Tip: 16 related IOCs (2 IP, 1 domain, 1 URL, 0 email, 12 file hash) to this threat have been found.

Overlaps

Boggy SerpensBoggy Serpens Evolves Tactics: Hijacked Accounts and AI-Enhanced Malware Targeting Critical Infrastructure

Source: Palo Alto Networks - March 2026

Detection (five cases): 157[.]20.182.75, 64[.]7.198.12, 7ea4b307e84c8b32c0220eca13155a4cf66617241f96b8af26ce2db8115e3d53, fc4a7eed5cb18c52265622ac39a5cef31eec101c898b4016874458d2722ec430, reminders.trahum[.]org

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Understanding the UDPGangster Campaigns

A cyber espionage group deployed a malware tool called UDPGangster through phishing emails containing malicious Word documents. The malware allowed attackers to control infected systems remotely.

The activity is attributed to MuddyWater, a known Iranian-linked cyber espionage group active in the Middle East and surrounding regions.

The attackers aimed to steal files, execute remote commands, and potentially deploy other malware for long-term surveillance and control.

The campaigns specifically targeted Turkey, Israel, and Azerbaijan using localized lures. Although sectors were not explicitly named, the content suggests targeting of government and geopolitical entities.

Victims received phishing emails with attachments posing as official documents. When opened and macros enabled, a backdoor was installed, allowing attackers remote access via UDP.

These regions are of strategic geopolitical interest. The attackers likely sought intelligence or access to sensitive systems in government, foreign affairs, or infrastructure.

Avoid enabling macros in documents from unknown sources. Use email gateways with phishing detection, monitor systems for unusual UDP traffic, and ensure endpoint protection tools are updated.

This was a targeted campaign, though the malware has been observed in multiple countries, suggesting coordinated, regionally-focused espionage efforts.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights