Threat Intelligence, Phishing
Israel subjected to new MuddyWater spear-phishing attacks
Share
Two Israeli organizations have been targeted by Iranian state-backed threat operation MuddyWater, also known as Mango Sandstorm and Static Kitten, in a new spear-phishing campaign that distributed N-able's Advanced Monitoring Agent remote administration tool, according to The Hacker News.
MuddyWater's latest campaign, which was similar to the group's previous attacks deploying other remote access tools, involved phishing emails using an official Israeli Civil Service Commission memo as a lure, which redirected targets to an archive hosted on the new Storyblok file-sharing service, which featured an infection-initiating LNK file, an executable for Advanced Monitoring Agent execution, and hidden files, a report from Deep Instinct revealed.
"After the victim has been infected, the MuddyWater operator will connect to the infected host using the legitimate remote administration tool and will start doing reconnaissance on the target," said Deep Instinct.
MuddyWater has also been observed using the new MuddyC2Go command-and-control framework in its latest campaign, indicating the continuously advancing cyber capabilities of Iran.
Related Events
Related Terms
BackdoorDeauthentication AttackDeepfakeDictionary AttackDistributed ScansDomain HijackingDrive-by DownloadDumpster DivingPassword CrackingReconnaissanceGet daily email updates
SC Media's daily must-read of the most current and pressing daily news