#muddywater — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #muddywater, aggregated by home.social.
-
MuddyWater Exploits Ransomware Disguise for Cyber Espionage
The line between ransomware attacks and nation-state espionage is rapidly blurring, as cyber groups like MuddyWater now disguise their operations as financially motivated ransomware attacks to further their strategic objectives. MuddyWater, linked to Iran's Ministry of Intelligence and Security, has been caught posing as the Chaos ransomware group in…
-
----------------
🎯 Threat Intelligence: Seedworm (MuddyWater) Q1 2026 Espionage Campaign
===================Iran-linked espionage group Seedworm (aka MuddyWater, Temp Zagros, Static Kitten), attributed to Iran's MOIS, conducted a broad campaign in Q1 2026. At least nine organizations across nine countries on four continents were compromised, including a major South Korean electronics manufacturer (operators persisted for a full week in February 2026), a Middle Eastern international airport, government agencies, Southeast Asian industrial manufacturers, a Latin American financial-services provider, and educational institutions. Every target held information of intelligence value to Tehran.
🔹 Technical Details
The campaign relied on DLL sideloading with two pairs of legitimate, signed binaries:
1. Fortemedia fmapp.exe / fmapp.dll: Legitimate audio-driver utility abused to sideload a malicious DLL. Previously documented by Group-IB in Seedworm reporting.
2. SentinelOne sentinelmemoryscanner.exe / sentinelagentcore.dll: Legitimate, signed endpoint component abused to sideload malicious code. Using a security-product binary defeats path and signature-based detection and confuses triage.
Both malicious DLLs contain ChromElevator, a publicly available post-exploitation tool that steals passwords, cookies, and payment card data from Chromium-based browsers.
In both cases, node.exe was the parent process at execution time, indicating the sideloading was orchestrated by a Node.js script rather than user execution. A Node.js script was found embedded in an XML file on targeted hosts.
🔹 Analysis
This campaign reflects a tactical shift. Seedworm has historically been a prolific PowerShell user, but here PowerShell was delivered and orchestrated through Node.js. The group's previous campaign used Deno. This experimentation with scripting runtimes is likely an evasion measure.
Multiple credential theft and privilege escalation tools were deployed iteratively, suggesting operators worked through their toolkit searching for viable paths to elevated access. One credential harvester (SHA256: d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc) calls CredUIPromptForWindowsCredentialsW, triggering the standard Windows credential prompt to harvest credentials.
PowerShell scripts pulled from a staging server performed reconnaissance, screenshot capture, SAM hive theft, and SOCKS5 reverse-proxy tunnelling.
🔹 Attack Chain Analysis
• Initial Access: Not detailed in source
• Execution: Node.js scripts embedded in XML files orchestrate payload delivery
• Persistence: DLL sideloading via legitimate signed binaries
• Credential Access: ChromElevator for browser data; CredUIPromptForWindowsCredentialsW harvester
• Privilege Escalation: Iterative deployment of multiple escalation tools
• Collection: Screenshot capture, SAM hive theft
• C2: SOCKS5 reverse-proxy tunnelling🔹 Detection
• Hunt for node.exe as parent of unexpected processes, especially those loading signed binaries from non-standard paths
• Flag DLL sideloading patterns: fmapp.dll and sentinelagentcore.dll loaded from unusual locations
• Monitor for CredUIPromptForWindowsCredentialsW calls from suspicious processes
• Review SentinelOne and Fortemedia binary execution paths for anomalies🔹 Limitations
Source does not specify the initial access vector. Attribution to MOIS is described as "widely believed" rather than definitively confirmed. Campaign scope may exceed the nine confirmed organizations.
🔹 seedworm #muddywater #threatintelligence #dllsideloading #iran
🔗 Source: https://www.security.com/threat-intelligence/iran-seedworm-electronics
-
El ataque al Metro de Los Ángeles fue obra de hackers del gobierno iraní disfrazados de activistas
Lo que se presentó como un ataque de hacktivistas pro-iraníes al sistema de transporte más grande del sur de California resultó ser una operación de espionaje estatal. La firma israelí Gambit Security vinculó al grupo «Ababil of Minab» con el Ministerio de Inteligencia de Irán, revelando el robo de al menos 700 GB de datos internos de la LACMTA (Fuente Los Angeles Times).
Durante semanas, el ataque al Metro de Los Ángeles parecía obra de un grupo de hacktivistas radicales. Ahora se sabe que era Irán. Investigadores de seguridad determinaron que la brecha de marzo al sistema de transporte del condado de Los Ángeles (LACMTA) fue ejecutada por hackers respaldados por el gobierno iraní. La firma israelí Gambit Security atribuyó el ataque a operativos del Ministerio de Inteligencia y Seguridad del Estado de Irán (MOIS), señalando que la persona hacktivista «Ababil of Minab» es en realidad una fachada fabricada por el Estado iraní.
El alcance del robo es significativo. Los atacantes sustrajeron al menos 700 gigabytes de correos electrónicos, copias de seguridad y otros archivos de la LACMTA. Gambit Security descubrió los datos después de que quedaran expuestos accidentalmente en línea, y un rastro digital vinculó el servidor donde fueron encontrados con una operación de hackeo previamente conocida y atribuida a Teherán.
El impacto operativo fue real y duradero. La intrusión fue detectada alrededor del 16 de marzo, y aproximadamente dos semanas después el grupo Ababil apareció en línea reclamando haber borrado una enorme cantidad de datos en un ataque destructivo, publicando un video que supuestamente mostraba su acceso a la red del sistema de transporte. La brecha deshabilitó las pantallas de llegadas y los sistemas de tarjetas de transporte durante semanas, aunque el servicio de buses y trenes continuó operando.
La fachada del grupo no era inocente: su nombre lleva una carga geopolítica explícita. El nombre «Ababil of Minab» hace referencia al bombardeo de una escuela de niñas en la ciudad iraní de Minab, ocurrido el 28 de febrero, en el que funcionarios iraníes afirman que murieron más de 175 niños y maestros. El grupo es rastreado bajo los alias Black Shadow, Static Kitten y MuddyWater, y responde a un patrón reiterado de Irán de usar marcas hacktivistas falsas como cobertura para operaciones de inteligencia estatal.
Lo más inquietante del incidente es hasta dónde llegaron los atacantes dentro de la infraestructura crítica. La brecha alcanzó una pantalla de control en tiempo real de un patio de maniobras ferroviario, aunque no hay evidencia divulgada de que haya sido manipulada. Lo que hasta ahora ha caracterizado a estas campañas iraníes es la falta de capacidad operativa para interrumpir físicamente el servicio a nivel de control de trenes o redes eléctricas, limitándose al robo de datos y la publicación de capturas de pantalla para avergonzar al objetivo.
Ababil también reclamó ataques contra el sistema de transporte Tri-Rail en el sur de Florida, la empresa de rastreo vehicular Vyncs y la firma de infraestructura saudí Unimac. La LACMTA declinó comentar los hallazgos de Gambit, mientras que el FBI y la Agencia de Ciberseguridad e Infraestructura (CISA) no realizaron atribuciones públicas. El conflicto entre EE.UU. e Irán, que escaló dramáticamente en 2026, encontró así en el ciberespacio uno de sus frentes más silenciosos y persistentes.
#AabilofMinab #arielmcorg #ciberataque #ciberespionaje #ciberseguridad #GambitSecurity #hackers #infraestructuracritica #Iran #LACMTA #LAMetro #LosAngeles #MOIS #MuddyWater #PORTADA #SeguridadNacional #transporte -
MuddyWater usa il ransomware Chaos come falsa bandiera: l’Iran maschera lo spionaggio di Stato da cybercrime
Il gruppo APT iraniano MuddyWater ha condotto un'operazione di cyberspionaggio mascherandola da attacco ransomware Chaos. Rapid7 rivela come Microsoft Teams sia stato usato per rubare credenziali e bypassare l'MFA, con il vero obiettivo di esfiltrazione dati e persistenza a lungo termine: non l'estorsione finanziaria. -
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
#ChaosRaaSGroup #MuddyWater
https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/ -
Iran-Linked APT Exploits Ransomware Disguise for Espionage
MuddyWater, an Iran-linked APT group, has been caught exploiting a ransomware disguise to secretly infiltrate systems, using interactive tactics to harvest credentials and gain internal access. By masquerading as a Chaos ransomware affiliate, the group aimed to throw off detectives and cover its espionage tracks.
-
MuddyWater hackers exploit Chaos ransomware as cyber-espionage decoy
MuddyWater hackers have cleverly used Chaos ransomware as a decoy to mask their true intentions - and it's not about making a quick buck. Instead, their tactics suggest a more sinister goal, blurring the lines between state-sponsored espionage and cybercrime.
#Muddywater #Iran #Cyberespionage #Statesponsored #Ransomware
-
Operazione Olalampo: MuddyWater sfrutta Rust e Telegram per spiare il Medio Oriente
Dal gennaio 2026 il gruppo iraniano MuddyWater conduce una campagna di spionaggio contro organizzazioni del Medio Oriente e Nord Africa con quattro nuove famiglie di malware, una backdoor scritta in Rust e un canale C2 nascosto nei bot Telegram. Analisi approfondita dell'Operazione Olalampo. -
ChainShell: MuddyWater’s Russian MaaS Link
#MuddyWater #CastleRAT #TAG_150 #ChainShell #Dindoor
https://www.jumpsec.com/guides/chainshell-muddywater-russian-criminal-infrastructure/ -
Rapid7 Detection Coverage for Iran-Linked Cyber Activity
#MuddyWater #VoidManticore #HandalaHackTeam #CyberAv3ngers #Keymous+ #DieNet #NoName057(16) #CVE_2026_1281 #CVE_2024_4577 #CVE_2025_32433 #CVE_2025_52691 #CVE_2025_9316 #CVE_2026_21514
https://www.rapid7.com/blog/post/tr-detection-coverage-iran-linked-cyber-activity/ -
Clearing the Water: Unmasking an Attack Chain of MuddyWater
#MuddyWater
https://www.huntress.com/blog/muddywater-attack-chain -
Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed #Dindoor - All this, despite the ongoing conflict.
Read: https://hackread.com/iran-muddywater-hackers-us-dindoor-backdoor/
-
One more for good measure because why not:
host.services.cert.parsed.issuer_dn="cgWUqATNuKVKop+/nRG88+u7AEo2ulPc/6DzDNJyq3Q" -
Iranian Use of Cybercriminal Tactics in Destructive Cyber Attacks: 2026 Updates
#MuddyWater #HandalaHackTeam #SicariiRansomware
https://www.halcyon.ai/ransomware-alerts/iranian-use-of-cybercriminal-tactics-in-destructive-cyber-attacks-2026-updates -
MuddyWater: Snakes by the riverbank
#MuddyWater #MuddyViper
https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/ -
The Ghosts from MuddyWater are the silent, persistent access they planted during the 2025 war. Our new analysis reveals how they've evolved from a nuisance into a strategic threat capable of bridging the digital and physical worlds.
Read the article:
https://decodedintel.com/ghosts-from-muddywater
#MuddyWater #Iran #Israel #Cybersecurity #ThreatIntelligence #Geopolitics
-
MuddyWater’s Phoenix Backdoor Infects More Than 100 Government Organizations https://gbhackers.com/muddywaters-phoenix/ #CyberSecurityNews #cybersecurity #MuddyWater
-
Over 100 government organizations hit by a single, stealthy campaign. MuddyWater’s new Phoenix backdoor uses cutting-edge tactics to slip past top defenses. Could this signal a new era in cyber espionage?
#muddywater
#phoenixbackdoor
#statesponsored
#cyberespionage
#malwareanalysis -
Finding the Unknown Unknowns, Part 4 (NilePhish, SneakyChef, Muddy Water, and a bonus unc)
#UNK_SweetSpecter #MuddyWater
https://strikeready.com/blog/finding-the-unknown-unknowns-part-4/ -
Mapping the Infrastructure and Malware Ecosystem of MuddyWater
#MuddyWater #BugSleep #StealthCache #Phoenix
https://www.group-ib.com/blog/muddywater-infrastructure-malware/ -
CTI Analysis: Malicious Email Campaign
#MuddyWater
https://dreamgroup.com/blog-cti/ -
APT MuddyWater Deploys Multi-Stage Phishing to Target CFOs
#MuddyWater
https://hunt.io/blog/apt-muddywater-deploys-multi-stage-phishing-to-target-cfos