home.social

#muddywater — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #muddywater, aggregated by home.social.

fetched live
  1. Italy’s Po river runs low as drought threatens farms and water supplies

    At the confluence with the Ticino, boats now sit in shallow, muddy water surrounded by sand, algae and…
    #Italy #Europe #Europa #EU #muddywater #northernItaly #seasonalaverages #shallowchannel #waterlevels
    europesays.com/italy/39571/

  2. Italy’s Po river runs low as drought threatens farms and water supplies

    At the confluence with the Ticino, boats now sit in shallow, muddy water surrounded by sand, algae and…
    #Italy #Europe #Europa #EU #muddywater #northernItaly #seasonalaverages #shallowchannel #waterlevels
    europesays.com/italy/39567/

  3. MuddyWater Exploits Ransomware Disguise for Cyber Espionage

    The line between ransomware attacks and nation-state espionage is rapidly blurring, as cyber groups like MuddyWater now disguise their operations as financially motivated ransomware attacks to further their strategic objectives. MuddyWater, linked to Iran's Ministry of Intelligence and Security, has been caught posing as the Chaos ransomware group in…

    osintsights.com/muddywater-exp

    #Muddywater #CyberEspionage #NationState #Ransomware #Iran

  4. ----------------

    🎯 Threat Intelligence: Seedworm (MuddyWater) Q1 2026 Espionage Campaign
    ===================

    Iran-linked espionage group Seedworm (aka MuddyWater, Temp Zagros, Static Kitten), attributed to Iran's MOIS, conducted a broad campaign in Q1 2026. At least nine organizations across nine countries on four continents were compromised, including a major South Korean electronics manufacturer (operators persisted for a full week in February 2026), a Middle Eastern international airport, government agencies, Southeast Asian industrial manufacturers, a Latin American financial-services provider, and educational institutions. Every target held information of intelligence value to Tehran.

    🔹 Technical Details

    The campaign relied on DLL sideloading with two pairs of legitimate, signed binaries:

    1. Fortemedia fmapp.exe / fmapp.dll: Legitimate audio-driver utility abused to sideload a malicious DLL. Previously documented by Group-IB in Seedworm reporting.

    2. SentinelOne sentinelmemoryscanner.exe / sentinelagentcore.dll: Legitimate, signed endpoint component abused to sideload malicious code. Using a security-product binary defeats path and signature-based detection and confuses triage.

    Both malicious DLLs contain ChromElevator, a publicly available post-exploitation tool that steals passwords, cookies, and payment card data from Chromium-based browsers.

    In both cases, node.exe was the parent process at execution time, indicating the sideloading was orchestrated by a Node.js script rather than user execution. A Node.js script was found embedded in an XML file on targeted hosts.

    🔹 Analysis

    This campaign reflects a tactical shift. Seedworm has historically been a prolific PowerShell user, but here PowerShell was delivered and orchestrated through Node.js. The group's previous campaign used Deno. This experimentation with scripting runtimes is likely an evasion measure.

    Multiple credential theft and privilege escalation tools were deployed iteratively, suggesting operators worked through their toolkit searching for viable paths to elevated access. One credential harvester (SHA256: d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc) calls CredUIPromptForWindowsCredentialsW, triggering the standard Windows credential prompt to harvest credentials.

    PowerShell scripts pulled from a staging server performed reconnaissance, screenshot capture, SAM hive theft, and SOCKS5 reverse-proxy tunnelling.

    🔹 Attack Chain Analysis
    • Initial Access: Not detailed in source
    • Execution: Node.js scripts embedded in XML files orchestrate payload delivery
    • Persistence: DLL sideloading via legitimate signed binaries
    • Credential Access: ChromElevator for browser data; CredUIPromptForWindowsCredentialsW harvester
    • Privilege Escalation: Iterative deployment of multiple escalation tools
    • Collection: Screenshot capture, SAM hive theft
    • C2: SOCKS5 reverse-proxy tunnelling

    🔹 Detection
    • Hunt for node.exe as parent of unexpected processes, especially those loading signed binaries from non-standard paths
    • Flag DLL sideloading patterns: fmapp.dll and sentinelagentcore.dll loaded from unusual locations
    • Monitor for CredUIPromptForWindowsCredentialsW calls from suspicious processes
    • Review SentinelOne and Fortemedia binary execution paths for anomalies

    🔹 Limitations

    Source does not specify the initial access vector. Attribution to MOIS is described as "widely believed" rather than definitively confirmed. Campaign scope may exceed the nine confirmed organizations.

    🔹 seedworm #muddywater #threatintelligence #dllsideloading #iran

    🔗 Source: security.com/threat-intelligen

  5. El ataque al Metro de Los Ángeles fue obra de hackers del gobierno iraní disfrazados de activistas

    Lo que se presentó como un ataque de hacktivistas pro-iraníes al sistema de transporte más grande del sur de California resultó ser una operación de espionaje estatal. La firma israelí Gambit Security vinculó al grupo «Ababil of Minab» con el Ministerio de Inteligencia de Irán, revelando el robo de al menos 700 GB de datos internos de la LACMTA (Fuente Los Angeles Times).

    Durante semanas, el ataque al Metro de Los Ángeles parecía obra de un grupo de hacktivistas radicales. Ahora se sabe que era Irán. Investigadores de seguridad determinaron que la brecha de marzo al sistema de transporte del condado de Los Ángeles (LACMTA) fue ejecutada por hackers respaldados por el gobierno iraní. La firma israelí Gambit Security atribuyó el ataque a operativos del Ministerio de Inteligencia y Seguridad del Estado de Irán (MOIS), señalando que la persona hacktivista «Ababil of Minab» es en realidad una fachada fabricada por el Estado iraní.

    El alcance del robo es significativo. Los atacantes sustrajeron al menos 700 gigabytes de correos electrónicos, copias de seguridad y otros archivos de la LACMTA. Gambit Security descubrió los datos después de que quedaran expuestos accidentalmente en línea, y un rastro digital vinculó el servidor donde fueron encontrados con una operación de hackeo previamente conocida y atribuida a Teherán.

    El impacto operativo fue real y duradero. La intrusión fue detectada alrededor del 16 de marzo, y aproximadamente dos semanas después el grupo Ababil apareció en línea reclamando haber borrado una enorme cantidad de datos en un ataque destructivo, publicando un video que supuestamente mostraba su acceso a la red del sistema de transporte. La brecha deshabilitó las pantallas de llegadas y los sistemas de tarjetas de transporte durante semanas, aunque el servicio de buses y trenes continuó operando.

    La fachada del grupo no era inocente: su nombre lleva una carga geopolítica explícita. El nombre «Ababil of Minab» hace referencia al bombardeo de una escuela de niñas en la ciudad iraní de Minab, ocurrido el 28 de febrero, en el que funcionarios iraníes afirman que murieron más de 175 niños y maestros. El grupo es rastreado bajo los alias Black Shadow, Static Kitten y MuddyWater, y responde a un patrón reiterado de Irán de usar marcas hacktivistas falsas como cobertura para operaciones de inteligencia estatal.

    Lo más inquietante del incidente es hasta dónde llegaron los atacantes dentro de la infraestructura crítica. La brecha alcanzó una pantalla de control en tiempo real de un patio de maniobras ferroviario, aunque no hay evidencia divulgada de que haya sido manipulada. Lo que hasta ahora ha caracterizado a estas campañas iraníes es la falta de capacidad operativa para interrumpir físicamente el servicio a nivel de control de trenes o redes eléctricas, limitándose al robo de datos y la publicación de capturas de pantalla para avergonzar al objetivo.

    Ababil también reclamó ataques contra el sistema de transporte Tri-Rail en el sur de Florida, la empresa de rastreo vehicular Vyncs y la firma de infraestructura saudí Unimac. La LACMTA declinó comentar los hallazgos de Gambit, mientras que el FBI y la Agencia de Ciberseguridad e Infraestructura (CISA) no realizaron atribuciones públicas. El conflicto entre EE.UU. e Irán, que escaló dramáticamente en 2026, encontró así en el ciberespacio uno de sus frentes más silenciosos y persistentes.

    #AabilofMinab #arielmcorg #ciberataque #ciberespionaje #ciberseguridad #GambitSecurity #hackers #infraestructuracritica #Iran #LACMTA #LAMetro #LosAngeles #MOIS #MuddyWater #PORTADA #SeguridadNacional #transporte
  6. MuddyWater Exploits DLL Side-Loading in Global Espionage Push

    MuddyWater hackers have launched a massive global espionage campaign, infiltrating at least nine organizations across four continents by cleverly disguising malicious code as legitimate software. They used a sneaky trick called DLL side-loading to quietly steal credentials and browser data.

    osintsights.com/muddywater-exp

    #Muddywater #DllSideloading #GlobalEspionage #Apt #EmergingThreats

  7. 📰 Iranian APT MuddyWater Masquerades as Ransomware Group in Microsoft Teams-Based Espionage Campaign

    ⚠️ Iranian APT MuddyWater targets orgs via Microsoft Teams, posing as a ransomware group. The real goal: espionage & data theft. Attackers trick users in screen-shares to steal credentials, bypassing MFA. #MuddyWater #CyberEspionage #ThreatIntel

    🔗 cyber.netsecops.io/articles/ir

  8. Iranian Hackers Target Electronics Maker in Global Espionage Push

    Iran-linked hackers, known as MuddyWater, infiltrated a major South Korean electronics manufacturer's network for a week in February 2026, as part of a massive global cyber-espionage campaign targeting nine high-profile organizations across multiple sectors and countries.

    osintsights.com/iranian-hacker

    #Muddywater #Seedworm #CyberEspionage #DllSideloading #Chromelevator

  9. 📰 Iranian APT MuddyWater Masquerades as Ransomware Group in Microsoft Teams-Based Espionage Campaign

    ⚠️ Iranian APT MuddyWater targets orgs via Microsoft Teams, posing as a ransomware group. The real goal: espionage & data theft. Attackers trick users in screen-shares to steal credentials, bypassing MFA. #MuddyWater #CyberEspionage #ThreatIntel

    🔗 cyber.netsecops.io

  10. MuddyWater Leverages Microsoft Teams for Credential Theft in False-Flag Ransomware Attack Microsoft Teams Social Engineering Phishing The Iranian-related APT (MuddyWater/Seedworm) targeted Microsof...

    #Ransomware #credential #false-flag #iranian #hacker #microsoft #teams #muddywater #ransomware #theft

    Origin | Interest | Match
  11. 📰 Iranian APT MuddyWater Masquerades as Ransomware Group in Microsoft Teams-Based Espionage Campaign

    ⚠️ Iranian APT MuddyWater targets orgs via Microsoft Teams, posing as a ransomware group. The real goal: espionage & data theft. Attackers trick users in screen-shares to steal credentials, bypassing MFA. #MuddyWater #CyberEspionage #ThreatIntel

    🔗 cyber.netsecops.io

  12. MuddyWater usa il ransomware Chaos come falsa bandiera: l’Iran maschera lo spionaggio di Stato da cybercrime

    Il gruppo APT iraniano MuddyWater ha condotto un'operazione di cyberspionaggio mascherandola da attacco ransomware Chaos. Rapid7 rivela come Microsoft Teams sia stato usato per rubare credenziali e bypassare l'MFA, con il vero obiettivo di esfiltrazione dati e persistenza a lungo termine: non l'estorsione finanziaria.

    insicurezzadigitale.com/muddyw

  13. MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack The Iranian state-sponsored hacking group known as MuddyWater (also known as Mango Sandstorm, Seedworm, and Stat...

    #Cyber #Security #Attack #Credentials #False #Flag #Microsoft #MuddyWater #Ransomware #Steal #Teams

    Origin | Interest | Match
  14. MuddyWater Exploits Microsoft Teams in False Flag Ransomware Attacks

    MuddyWater hackers are impersonating Chaos ransomware affiliates, using clever social engineering tactics via Microsoft Teams to steal credentials and gain access to sensitive systems. Their sophisticated campaign involves interactive screen-sharing and manipulation of multi-factor authentication.

    osintsights.com/muddywater-exp

    #Muddywater #MicrosoftTeams #RansomwareAttacks #MfaBypass #FalseFlag

  15. Iran-Linked APT Exploits Ransomware Disguise for Espionage

    MuddyWater, an Iran-linked APT group, has been caught exploiting a ransomware disguise to secretly infiltrate systems, using interactive tactics to harvest credentials and gain internal access. By masquerading as a Chaos ransomware affiliate, the group aimed to throw off detectives and cover its espionage tracks.

    osintsights.com/iran-linked-ap

    #Muddywater #Apt #Iran #MfaBypass #Ransomware

  16. MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy

    MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.

    osintsights.com/muddywater-hac

    #Muddywater #Iran #Cyberespionage #Statesponsored #Ransomware

  17. MuddyWater: Iran’s Adaptive Cyber Espionage Machine | Hive Pro

    Pulse ID: 69f84c389579fc3ebe32d238
    Pulse Link: otx.alienvault.com/pulse/69f84
    Pulse Author: Tr1sa111
    Created: 2026-05-04 07:35:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #Iran #Mac #MuddyWater #OTX #OpenThreatExchange #bot #Tr1sa111

  18. Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente

    Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in Rust e un canale C2 nascosto nei bot Telegram. Analisi approfondita dell'Operazione Olalampo.

    insicurezzadigitale.com/operaz

  19. Iran-linked cyber espionage surges across Middle East as conflict tensions rise, researchers say

    New research from Proofpoint shows that escalating tensions involving Iran have coincided with a surge in cyber espionage…
    #Israel #News #APT42 #CharmingKitten #CheckPoint #CobaltStrike #CyberEspionage #cyberoperations #cybercrime #espionage #HandalaHack #MintSandstorm #MuddyWater #phishing #proofpoint #TA453 #VoidManticore
    europesays.com/2840087/

  20. InfoSec News Nuggets 03/10/2026 APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military ESET researchers have published a deep-dive on Russia’s APT28 (Fancy Bear/Sednit), revealin...

    #InfoSec #News #Nuggets #AboutDFIR #BEARDSHELL #MuddyWater #news #nuggets

    Origin | Interest | Match
  21. Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed #Dindoor - All this, despite the ongoing conflict.

    Read: hackread.com/iran-muddywater-h

    #CyberSecurity #Iran #Israel #US #MuddyWater #Malware

  22. One more for good measure because why not:

    host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q"

    #ThreatIntel #CTI #MuddyWater

  23. Iran-Linked MuddyWater Deploys Rust-Based RAT in Middle East Phishing Attacks Iranian-linked group MuddyWater has deployed RustyWater, a Rust-based RAT, via spear-phishing attacks on Middle Eastern...

    #CybersecurityUpdate #Middle #East #cyber #th #MuddyWater #hacking #group #Rust-based #malware #RustyWater

    Origin | Interest | Match
  24. Windows Systems Under Attack as MuddyWater Hackers Use UDPGangster Backdoor to Bypass Defenses Cybersecurity researchers at FortiGuard Labs have uncovered new phishing campaigns by the MuddyWater t...

    #Cyber #Security #News #Windows #MuddyWater #Hackers

    Origin | Interest | Match
  25. The Ghosts from MuddyWater are the silent, persistent access they planted during the 2025 war. Our new analysis reveals how they've evolved from a nuisance into a strategic threat capable of bridging the digital and physical worlds.

    Read the article:

    decodedintel.com/ghosts-from-m

    #MuddyWater #Iran #Israel #Cybersecurity #ThreatIntelligence #Geopolitics

  26. Over 100 government organizations hit by a single, stealthy campaign. MuddyWater’s new Phoenix backdoor uses cutting-edge tactics to slip past top defenses. Could this signal a new era in cyber espionage?

    thedefendopsdiaries.com/the-ph

    #muddywater
    #phoenixbackdoor
    #statesponsored
    #cyberespionage
    #malwareanalysis

  27. Floods trap people in cars in Spain’s Catalonia region

    Floods caused by torrential rain have left a number of people trapped in vehicles in Spain’s north-eastern Catalonia…
    #Spain #ES #Europe #Europa #EU #Cataloniaregion #civilprotection #muddywater #spain #Tarragonaprovince #TORRENTIALRAIN
    europesays.com/2488060/

  28. Global Cyber Espionage Campaign by APT MuddyWater Targeting Financial Executives

    Pulse ID: 68a7618a17a2e794636f52ed
    Pulse Link: otx.alienvault.com/pulse/68a76
    Pulse Author: cryptocti
    Created: 2025-08-21 18:12:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #MuddyWater #OTX #OpenThreatExchange #bot #cryptocti

  29. Our colleagues at Check Point Research have also published a report on this new #MuddyWater implant and related campaigns.

    research.checkpoint.com/2024/n

  30. Deep Instinct reports on the latest activity from Iranian state-sponsored APT MuddyWater, including the latest attack framework "DarkBeatC2." It's a comprehensive look at Iranian attacks on Israel and the recent supply-chain attack targeting IT provider Rashim which led to access to other organizations through VPN. IOC are provided. 🔗 deepinstinct.com/blog/darkbeat

    #Iran #Cyberespionage #MuddyWater #LordNemesis #threatintel #IOC

  31. Malwation reports new attacks against Israel, Africa, and Turkiye by the Iranian state-sponsored APT MuddyWater. This includes the use of Atera and ConnectWise ScreenConnect remote administration management (RMM) software. Malwation describes attack chain and provides IOC. 🔗 malwation.com/blog/new-muddywa

    #MuddyWater #Iran #cyberespionage #threatintel #IOC

Share
Share on Mastodon

Enter the server where you have an account.