MuddyWater Targets Critical Infrastructure in Israel and Egypt with New Custom Malware
ESET researchers have identified a new cyberespionage campaign by MuddyWater, an Iran-aligned advanced persistent threat (APT) group, primarily targeting critical infrastructure organizations in Israel and Egypt. This operation marks a significant evolution in the group's tactics, shifting from previously noisy methods to a more sophisticated and refined approach. The attackers deployed undocumented custom tools, including the Fooder loader, which masquerades as the classic Snake game to delay execution and evade automated analysis. This loader executes MuddyViper, a new C/C++ backdoor capable of collecting system information, executing commands, and exfiltrating credentials and browser data. Notably, MuddyWater adopted the Windows Cryptographic Next Generation (CNG) API, a technique unique among Iran-aligned groups. The campaign also utilized credential stealers like CE-Notes and LP-Notes, alongside go-socks5 reverse tunneling tools. Operators deliberately avoided interactive hands-on-keyboard sessions to minimize detection risks. This activity underscores the group's persistent focus on government and telecommunications sectors in the Middle East, leveraging improved defense evasion techniques to maintain long-term access and steal sensitive data from high-value targets.
Wire timeline
MuddyWater Targets Critical Infrastructure in Israel and Egypt with New Custom Malware
ESET researchers have identified a new cyberespionage campaign by MuddyWater, an Iran-aligned advanced persistent threat (APT) group, primarily targeting critical infrastructure organizations in Israel and Egypt. This operation marks a significant evolution in the group's tactics, shifting from previously noisy methods to a more sophisticated and refined approach. The attackers deployed undocumented custom tools, including the Fooder loader, which masquerades as the classic Snake game to delay execution and evade automated analysis. This loader executes MuddyViper, a new C/C++ backdoor capable of collecting system information, executing commands, and exfiltrating credentials and browser data. Notably, MuddyWater adopted the Windows Cryptographic Next Generation (CNG) API, a technique unique among Iran-aligned groups. The campaign also utilized credential stealers like CE-Notes and LP-Notes, alongside go-socks5 reverse tunneling tools. Operators deliberately avoided interactive hands-on-keyboard sessions to minimize detection risks. This activity underscores the group's persistent focus on government and telecommunications sectors in the Middle East, leveraging improved defense evasion techniques to maintain long-term access and steal sensitive data from high-value targets.
WeLiveSecurity