home.social

#muddywater — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #muddywater, aggregated by home.social.

fetched live
  1. Italy’s Po river runs low as drought threatens farms and water supplies

    At the confluence with the Ticino, boats now sit in shallow, muddy water surrounded by sand, algae and…
    #Italy #Europe #Europa #EU #muddywater #northernItaly #seasonalaverages #shallowchannel #waterlevels
    europesays.com/italy/39571/

  2. Italy’s Po river runs low as drought threatens farms and water supplies

    At the confluence with the Ticino, boats now sit in shallow, muddy water surrounded by sand, algae and…
    #Italy #Europe #Europa #EU #muddywater #northernItaly #seasonalaverages #shallowchannel #waterlevels
    europesays.com/italy/39567/

  3. MuddyWater Exploits Ransomware Disguise for Cyber Espionage

    The line between ransomware attacks and nation-state espionage is rapidly blurring, as cyber groups like MuddyWater now disguise their operations as financially motivated ransomware attacks to further their strategic objectives. MuddyWater, linked to Iran's Ministry of Intelligence and Security, has been caught posing as the Chaos ransomware group in…

    osintsights.com/muddywater-exp

    #Muddywater #CyberEspionage #NationState #Ransomware #Iran

  4. ----------------

    🎯 Threat Intelligence: Seedworm (MuddyWater) Q1 2026 Espionage Campaign
    ===================

    Iran-linked espionage group Seedworm (aka MuddyWater, Temp Zagros, Static Kitten), attributed to Iran's MOIS, conducted a broad campaign in Q1 2026. At least nine organizations across nine countries on four continents were compromised, including a major South Korean electronics manufacturer (operators persisted for a full week in February 2026), a Middle Eastern international airport, government agencies, Southeast Asian industrial manufacturers, a Latin American financial-services provider, and educational institutions. Every target held information of intelligence value to Tehran.

    🔹 Technical Details

    The campaign relied on DLL sideloading with two pairs of legitimate, signed binaries:

    1. Fortemedia fmapp.exe / fmapp.dll: Legitimate audio-driver utility abused to sideload a malicious DLL. Previously documented by Group-IB in Seedworm reporting.

    2. SentinelOne sentinelmemoryscanner.exe / sentinelagentcore.dll: Legitimate, signed endpoint component abused to sideload malicious code. Using a security-product binary defeats path and signature-based detection and confuses triage.

    Both malicious DLLs contain ChromElevator, a publicly available post-exploitation tool that steals passwords, cookies, and payment card data from Chromium-based browsers.

    In both cases, node.exe was the parent process at execution time, indicating the sideloading was orchestrated by a Node.js script rather than user execution. A Node.js script was found embedded in an XML file on targeted hosts.

    🔹 Analysis

    This campaign reflects a tactical shift. Seedworm has historically been a prolific PowerShell user, but here PowerShell was delivered and orchestrated through Node.js. The group's previous campaign used Deno. This experimentation with scripting runtimes is likely an evasion measure.

    Multiple credential theft and privilege escalation tools were deployed iteratively, suggesting operators worked through their toolkit searching for viable paths to elevated access. One credential harvester (SHA256: d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc) calls CredUIPromptForWindowsCredentialsW, triggering the standard Windows credential prompt to harvest credentials.

    PowerShell scripts pulled from a staging server performed reconnaissance, screenshot capture, SAM hive theft, and SOCKS5 reverse-proxy tunnelling.

    🔹 Attack Chain Analysis
    • Initial Access: Not detailed in source
    • Execution: Node.js scripts embedded in XML files orchestrate payload delivery
    • Persistence: DLL sideloading via legitimate signed binaries
    • Credential Access: ChromElevator for browser data; CredUIPromptForWindowsCredentialsW harvester
    • Privilege Escalation: Iterative deployment of multiple escalation tools
    • Collection: Screenshot capture, SAM hive theft
    • C2: SOCKS5 reverse-proxy tunnelling

    🔹 Detection
    • Hunt for node.exe as parent of unexpected processes, especially those loading signed binaries from non-standard paths
    • Flag DLL sideloading patterns: fmapp.dll and sentinelagentcore.dll loaded from unusual locations
    • Monitor for CredUIPromptForWindowsCredentialsW calls from suspicious processes
    • Review SentinelOne and Fortemedia binary execution paths for anomalies

    🔹 Limitations

    Source does not specify the initial access vector. Attribution to MOIS is described as "widely believed" rather than definitively confirmed. Campaign scope may exceed the nine confirmed organizations.

    🔹 seedworm #muddywater #threatintelligence #dllsideloading #iran

    🔗 Source: security.com/threat-intelligen

  5. ----------------

    🎯 Threat Intelligence: Seedworm (MuddyWater) Q1 2026 Espionage Campaign
    ===================

    Iran-linked espionage group Seedworm (aka MuddyWater, Temp Zagros, Static Kitten), attributed to Iran's MOIS, conducted a broad campaign in Q1 2026. At least nine organizations across nine countries on four continents were compromised, including a major South Korean electronics manufacturer (operators persisted for a full week in February 2026), a Middle Eastern international airport, government agencies, Southeast Asian industrial manufacturers, a Latin American financial-services provider, and educational institutions. Every target held information of intelligence value to Tehran.

    🔹 Technical Details

    The campaign relied on DLL sideloading with two pairs of legitimate, signed binaries:

    1. Fortemedia fmapp.exe / fmapp.dll: Legitimate audio-driver utility abused to sideload a malicious DLL. Previously documented by Group-IB in Seedworm reporting.

    2. SentinelOne sentinelmemoryscanner.exe / sentinelagentcore.dll: Legitimate, signed endpoint component abused to sideload malicious code. Using a security-product binary defeats path and signature-based detection and confuses triage.

    Both malicious DLLs contain ChromElevator, a publicly available post-exploitation tool that steals passwords, cookies, and payment card data from Chromium-based browsers.

    In both cases, node.exe was the parent process at execution time, indicating the sideloading was orchestrated by a Node.js script rather than user execution. A Node.js script was found embedded in an XML file on targeted hosts.

    🔹 Analysis

    This campaign reflects a tactical shift. Seedworm has historically been a prolific PowerShell user, but here PowerShell was delivered and orchestrated through Node.js. The group's previous campaign used Deno. This experimentation with scripting runtimes is likely an evasion measure.

    Multiple credential theft and privilege escalation tools were deployed iteratively, suggesting operators worked through their toolkit searching for viable paths to elevated access. One credential harvester (SHA256: d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc) calls CredUIPromptForWindowsCredentialsW, triggering the standard Windows credential prompt to harvest credentials.

    PowerShell scripts pulled from a staging server performed reconnaissance, screenshot capture, SAM hive theft, and SOCKS5 reverse-proxy tunnelling.

    🔹 Attack Chain Analysis
    • Initial Access: Not detailed in source
    • Execution: Node.js scripts embedded in XML files orchestrate payload delivery
    • Persistence: DLL sideloading via legitimate signed binaries
    • Credential Access: ChromElevator for browser data; CredUIPromptForWindowsCredentialsW harvester
    • Privilege Escalation: Iterative deployment of multiple escalation tools
    • Collection: Screenshot capture, SAM hive theft
    • C2: SOCKS5 reverse-proxy tunnelling

    🔹 Detection
    • Hunt for node.exe as parent of unexpected processes, especially those loading signed binaries from non-standard paths
    • Flag DLL sideloading patterns: fmapp.dll and sentinelagentcore.dll loaded from unusual locations
    • Monitor for CredUIPromptForWindowsCredentialsW calls from suspicious processes
    • Review SentinelOne and Fortemedia binary execution paths for anomalies

    🔹 Limitations

    Source does not specify the initial access vector. Attribution to MOIS is described as "widely believed" rather than definitively confirmed. Campaign scope may exceed the nine confirmed organizations.

    🔹 seedworm #muddywater #threatintelligence #dllsideloading #iran

    🔗 Source: security.com/threat-intelligen

  6. El ataque al Metro de Los Ángeles fue obra de hackers del gobierno iraní disfrazados de activistas

    Lo que se presentó como un ataque de hacktivistas pro-iraníes al sistema de transporte más grande del sur de California resultó ser una operación de espionaje estatal. La firma israelí Gambit Security vinculó al grupo «Ababil of Minab» con el Ministerio de Inteligencia de Irán, revelando el robo de al menos 700 GB de datos internos de la LACMTA (Fuente Los Angeles Times).

    Durante semanas, el ataque al Metro de Los Ángeles parecía obra de un grupo de hacktivistas radicales. Ahora se sabe que era Irán. Investigadores de seguridad determinaron que la brecha de marzo al sistema de transporte del condado de Los Ángeles (LACMTA) fue ejecutada por hackers respaldados por el gobierno iraní. La firma israelí Gambit Security atribuyó el ataque a operativos del Ministerio de Inteligencia y Seguridad del Estado de Irán (MOIS), señalando que la persona hacktivista «Ababil of Minab» es en realidad una fachada fabricada por el Estado iraní.

    El alcance del robo es significativo. Los atacantes sustrajeron al menos 700 gigabytes de correos electrónicos, copias de seguridad y otros archivos de la LACMTA. Gambit Security descubrió los datos después de que quedaran expuestos accidentalmente en línea, y un rastro digital vinculó el servidor donde fueron encontrados con una operación de hackeo previamente conocida y atribuida a Teherán.

    El impacto operativo fue real y duradero. La intrusión fue detectada alrededor del 16 de marzo, y aproximadamente dos semanas después el grupo Ababil apareció en línea reclamando haber borrado una enorme cantidad de datos en un ataque destructivo, publicando un video que supuestamente mostraba su acceso a la red del sistema de transporte. La brecha deshabilitó las pantallas de llegadas y los sistemas de tarjetas de transporte durante semanas, aunque el servicio de buses y trenes continuó operando.

    La fachada del grupo no era inocente: su nombre lleva una carga geopolítica explícita. El nombre «Ababil of Minab» hace referencia al bombardeo de una escuela de niñas en la ciudad iraní de Minab, ocurrido el 28 de febrero, en el que funcionarios iraníes afirman que murieron más de 175 niños y maestros. El grupo es rastreado bajo los alias Black Shadow, Static Kitten y MuddyWater, y responde a un patrón reiterado de Irán de usar marcas hacktivistas falsas como cobertura para operaciones de inteligencia estatal.

    Lo más inquietante del incidente es hasta dónde llegaron los atacantes dentro de la infraestructura crítica. La brecha alcanzó una pantalla de control en tiempo real de un patio de maniobras ferroviario, aunque no hay evidencia divulgada de que haya sido manipulada. Lo que hasta ahora ha caracterizado a estas campañas iraníes es la falta de capacidad operativa para interrumpir físicamente el servicio a nivel de control de trenes o redes eléctricas, limitándose al robo de datos y la publicación de capturas de pantalla para avergonzar al objetivo.

    Ababil también reclamó ataques contra el sistema de transporte Tri-Rail en el sur de Florida, la empresa de rastreo vehicular Vyncs y la firma de infraestructura saudí Unimac. La LACMTA declinó comentar los hallazgos de Gambit, mientras que el FBI y la Agencia de Ciberseguridad e Infraestructura (CISA) no realizaron atribuciones públicas. El conflicto entre EE.UU. e Irán, que escaló dramáticamente en 2026, encontró así en el ciberespacio uno de sus frentes más silenciosos y persistentes.

    #AabilofMinab #arielmcorg #ciberataque #ciberespionaje #ciberseguridad #GambitSecurity #hackers #infraestructuracritica #Iran #LACMTA #LAMetro #LosAngeles #MOIS #MuddyWater #PORTADA #SeguridadNacional #transporte
  7. MuddyWater Exploits DLL Side-Loading in Global Espionage Push

    MuddyWater hackers have launched a massive global espionage campaign, infiltrating at least nine organizations across four continents by cleverly disguising malicious code as legitimate software. They used a sneaky trick called DLL side-loading to quietly steal credentials and browser data.

    osintsights.com/muddywater-exp

    #Muddywater #DllSideloading #GlobalEspionage #Apt #EmergingThreats

  8. 📰 Iranian APT MuddyWater Masquerades as Ransomware Group in Microsoft Teams-Based Espionage Campaign

    ⚠️ Iranian APT MuddyWater targets orgs via Microsoft Teams, posing as a ransomware group. The real goal: espionage & data theft. Attackers trick users in screen-shares to steal credentials, bypassing MFA. #MuddyWater #CyberEspionage #ThreatIntel

    🔗 cyber.netsecops.io/articles/ir

  9. Iranian Hackers Target Electronics Maker in Global Espionage Push

    Iran-linked hackers, known as MuddyWater, infiltrated a major South Korean electronics manufacturer's network for a week in February 2026, as part of a massive global cyber-espionage campaign targeting nine high-profile organizations across multiple sectors and countries.

    osintsights.com/iranian-hacker

    #Muddywater #Seedworm #CyberEspionage #DllSideloading #Chromelevator

  10. 📰 Iranian APT MuddyWater Masquerades as Ransomware Group in Microsoft Teams-Based Espionage Campaign

    ⚠️ Iranian APT MuddyWater targets orgs via Microsoft Teams, posing as a ransomware group. The real goal: espionage & data theft. Attackers trick users in screen-shares to steal credentials, bypassing MFA. #MuddyWater #CyberEspionage #ThreatIntel

    🔗 cyber.netsecops.io

  11. 📰 Iranian APT MuddyWater Masquerades as Ransomware Group in Microsoft Teams-Based Espionage Campaign

    ⚠️ Iranian APT MuddyWater targets orgs via Microsoft Teams, posing as a ransomware group. The real goal: espionage & data theft. Attackers trick users in screen-shares to steal credentials, bypassing MFA. #MuddyWater #CyberEspionage #ThreatIntel

    🔗 cyber.netsecops.io

  12. MuddyWater usa il ransomware Chaos come falsa bandiera: l’Iran maschera lo spionaggio di Stato da cybercrime

    Il gruppo APT iraniano MuddyWater ha condotto un'operazione di cyberspionaggio mascherandola da attacco ransomware Chaos. Rapid7 rivela come Microsoft Teams sia stato usato per rubare credenziali e bypassare l'MFA, con il vero obiettivo di esfiltrazione dati e persistenza a lungo termine: non l'estorsione finanziaria.

    insicurezzadigitale.com/muddyw

  13. MuddyWater usa il ransomware Chaos come falsa bandiera: l’Iran maschera lo spionaggio di Stato da cybercrime

    Il gruppo APT iraniano MuddyWater ha condotto un'operazione di cyberspionaggio mascherandola da attacco ransomware Chaos. Rapid7 rivela come Microsoft Teams sia stato usato per rubare credenziali e bypassare l'MFA, con il vero obiettivo di esfiltrazione dati e persistenza a lungo termine: non l'estorsione finanziaria.

    insicurezzadigitale.com/muddyw

  14. MuddyWater usa il ransomware Chaos come falsa bandiera: l’Iran maschera lo spionaggio di Stato da cybercrime

    Il gruppo APT iraniano MuddyWater ha condotto un'operazione di cyberspionaggio mascherandola da attacco ransomware Chaos. Rapid7 rivela come Microsoft Teams sia stato usato per rubare credenziali e bypassare l'MFA, con il vero obiettivo di esfiltrazione dati e persistenza a lungo termine: non l'estorsione finanziaria.

    insicurezzadigitale.com/muddyw

  15. MuddyWater usa il ransomware Chaos come falsa bandiera: l’Iran maschera lo spionaggio di Stato da cybercrime

    Il gruppo APT iraniano MuddyWater ha condotto un'operazione di cyberspionaggio mascherandola da attacco ransomware Chaos. Rapid7 rivela come Microsoft Teams sia stato usato per rubare credenziali e bypassare l'MFA, con il vero obiettivo di esfiltrazione dati e persistenza a lungo termine: non l'estorsione finanziaria.

    insicurezzadigitale.com/muddyw

  16. MuddyWater usa il ransomware Chaos come falsa bandiera: l’Iran maschera lo spionaggio di Stato da cybercrime

    Il gruppo APT iraniano MuddyWater ha condotto un'operazione di cyberspionaggio mascherandola da attacco ransomware Chaos. Rapid7 rivela come Microsoft Teams sia stato usato per rubare credenziali e bypassare l'MFA, con il vero obiettivo di esfiltrazione dati e persistenza a lungo termine: non l'estorsione finanziaria.

    insicurezzadigitale.com/muddyw

  17. MuddyWater Exploits Microsoft Teams in False Flag Ransomware Attacks

    MuddyWater hackers are impersonating Chaos ransomware affiliates, using clever social engineering tactics via Microsoft Teams to steal credentials and gain access to sensitive systems. Their sophisticated campaign involves interactive screen-sharing and manipulation of multi-factor authentication.

    osintsights.com/muddywater-exp

    #Muddywater #MicrosoftTeams #RansomwareAttacks #MfaBypass #FalseFlag

  18. Iran-Linked APT Exploits Ransomware Disguise for Espionage

    MuddyWater, an Iran-linked APT group, has been caught exploiting a ransomware disguise to secretly infiltrate systems, using interactive tactics to harvest credentials and gain internal access. By masquerading as a Chaos ransomware affiliate, the group aimed to throw off detectives and cover its espionage tracks.

    osintsights.com/iran-linked-ap

    #Muddywater #Apt #Iran #MfaBypass #Ransomware

  19. Iran-Linked APT Exploits Ransomware Disguise for Espionage

    MuddyWater, an Iran-linked APT group, has been caught exploiting a ransomware disguise to secretly infiltrate systems, using interactive tactics to harvest credentials and gain internal access. By masquerading as a Chaos ransomware affiliate, the group aimed to throw off detectives and cover its espionage tracks.

    osintsights.com/iran-linked-ap

    #Muddywater #Apt #Iran #MfaBypass #Ransomware

  20. MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy

    MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.

    osintsights.com/muddywater-hac

    #Muddywater #Iran #Cyberespionage #Statesponsored #Ransomware

  21. MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy

    MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.

    osintsights.com/muddywater-hac

    #Muddywater #Iran #Cyberespionage #Statesponsored #Ransomware

  22. Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente

    Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in Rust e un canale C2 nascosto nei bot Telegram. Analisi approfondita dell'Operazione Olalampo.

    insicurezzadigitale.com/operaz

  23. Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente

    Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in Rust e un canale C2 nascosto nei bot Telegram. Analisi approfondita dell'Operazione Olalampo.

    insicurezzadigitale.com/operaz

  24. Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente

    Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in Rust e un canale C2 nascosto nei bot Telegram. Analisi approfondita dell'Operazione Olalampo.

    insicurezzadigitale.com/operaz

  25. Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente

    Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in Rust e un canale C2 nascosto nei bot Telegram. Analisi approfondita dell'Operazione Olalampo.

    insicurezzadigitale.com/operaz

  26. Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente

    Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in Rust e un canale C2 nascosto nei bot Telegram. Analisi approfondita dell'Operazione Olalampo.

    insicurezzadigitale.com/operaz

  27. Iran-linked cyber espionage surges across Middle East as conflict tensions rise, researchers say

    New research from Proofpoint shows that escalating tensions involving Iran have coincided with a surge in cyber espionage…
    #Israel #News #APT42 #CharmingKitten #CheckPoint #CobaltStrike #CyberEspionage #cyberoperations #cybercrime #espionage #HandalaHack #MintSandstorm #MuddyWater #phishing #proofpoint #TA453 #VoidManticore
    europesays.com/2840087/

  28. Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed - All this, despite the ongoing conflict.

    Read: hackread.com/iran-muddywater-h

  29. Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed #Dindoor - All this, despite the ongoing conflict.

    Read: hackread.com/iran-muddywater-h

    #CyberSecurity #Iran #Israel #US #MuddyWater #Malware

  30. Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed #Dindoor - All this, despite the ongoing conflict.

    Read: hackread.com/iran-muddywater-h

    #CyberSecurity #Iran #Israel #US #MuddyWater #Malware

  31. Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed #Dindoor - All this, despite the ongoing conflict.

    Read: hackread.com/iran-muddywater-h

    #CyberSecurity #Iran #Israel #US #MuddyWater #Malware

  32. Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed #Dindoor - All this, despite the ongoing conflict.

    Read: hackread.com/iran-muddywater-h

    #CyberSecurity #Iran #Israel #US #MuddyWater #Malware

  33. One more for good measure because why not:

    host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q"

    #ThreatIntel #CTI #MuddyWater

  34. One more for good measure because why not:

    host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q"

    #ThreatIntel #CTI #MuddyWater

  35. One more for good measure because why not:

    host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q"

    #ThreatIntel #CTI #MuddyWater

  36. One more for good measure because why not:

    host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q"

    #ThreatIntel #CTI #MuddyWater

  37. One more for good measure because why not:

    host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q"

    #ThreatIntel #CTI #MuddyWater