Threat Actor 🇮🇷 Iran
MuddyWater
Also known as: TEMP.Zagros · Static Kitten · Seedworm · MERCURY · COBALT ULSTER · G0069 · ATK51 · Boggy Serpens · Mango Sandstorm · TA450 · Earth Vetala
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.
Indicators of Compromise 11
MITRE ATT&CK TTPs 16
T1003 T1027 T1059 T1059.001 T1059.007 T1071.001 T1074 T1074.001 T1082 T1090 T1090.003 T1105 T1219 T1566 T1573.001 T1588
OS Credential Dumping
Credential Access
Obfuscated Files or Information
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
JavaScript
Execution
Web Protocols
Command And Control
Data Staged
Collection
Local Data Staging
Collection
System Information Discovery
Discovery
Proxy
Command And Control
Multi-hop Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Remote Access Software
Command And Control
Phishing
Initial Access
Symmetric Cryptography
Command And Control
Obtain Capabilities
Resource Development
Source Articles
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is deploying a new Rust-based backdoor named msaRAT that leverages Chrome or Edge browsers to route command-and-control (C2) traffic, evading detection by avoiding direct network connections. The malware uses the Chrome DevTools Protocol to control a headless browser session and establishes encrypted communication via WebRTC through Twilio TURN servers and a Cloudflare Workers endpoint. This dual-layer infrastructure hides the attacker's true C2 server and complicates traceback efforts, while also bypassing firewalls and allowlists by blending with legitimate web traffic.
bleeping-computer ·5d ago
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.
hacker-news ·1w ago
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group linked to the Ministry of Intelligence and Security (MOIS), tracked as Cavern Manticore, has been using a new modular command-and-control (C2) framework named Cavern to target Israeli organizations, particularly in the IT and government sectors. The attack leverages DLL side-loading via SysAid's software update mechanism, deploying a trojanized DLL (uxtheme.dll) that communicates with a C2 server and downloads additional malicious modules. These modules enable reconnaissance, data theft, lateral movement, and tunneling, with a sophisticated .NET-based architecture using mixed compilation formats to hinder analysis. The group exploits trusted relationships in the software supply chain and has shifted from broad reconnaissance to targeted data exfiltration across Middle Eastern sectors.
hacker-news ·3w ago