Summary:
The cyber-espionage group MuddyWater has been active at least since 2017, and it has been implicated in several well-known attacks against organisations in the Middle East, Europe, and North America. Typically, MuddyWater's campaigns start with emails that spear-phish certain targets. The emails frequently include weaponized attachments or links to malicious websites while appearing to be genuine messages from reliable sources, such as government organisations. The attackers utilize a number of techniques to acquire information and move laterally through the network once they have taken control of a victim's system. The group has been employing legitimate remote-control software like Syncro, RemoteUtilities, and ScreenConnect. By doing this, MuddyWater is able to connect to user devices at any time, run arbitrary commands, and download and upload files. These tools cannot be discovered through ordinary security measures because they are legitimate and uncompromised, making it difficult to track their activity. SimpleHelp, a similar tool, was identified by researchers to be used by MuddyWater.[/subscribe_to_unlock_form]
Summary:
The cyber-espionage group MuddyWater has been active at least since 2017, and it has been implicated in several well-known attacks against organisations in the Middle East, Europe, and North America. Typically, MuddyWater's campaigns start with emails that spear-phish certain targets. The emails frequently include weaponized attachments or links to malicious websites while appearing to be genuine messages from reliable sources, such as government organisations. The attackers utilize a number of techniques to acquire information and move laterally through the network once they have taken control of a victim's system. The group has been employing legitimate remote-control software like Syncro, RemoteUtilities, and ScreenConnect. By doing this, MuddyWater is able to connect to user devices at any time, run arbitrary commands, and download and upload files. These tools cannot be discovered through ordinary security measures because they are legitimate and uncompromised, making it difficult to track their activity. SimpleHelp, a similar tool, was identified by researchers to be used by MuddyWater.[emaillocker id="1283"]
One of the key findings in the study is that MuddyWater's infrastructure has grown significantly in recent years. A large network of C&C servers, phishing domains, and other infrastructure are now maintained by the group, much of which is hosted on cloud-based platforms. This enables the group to launch new attack infrastructure fast and easily while evading detection by security solutions that rely on well-known malicious IP addresses or domains. Various specialized tools are included in MuddyWater's malware arsenal, including POWERSTATS, a PowerShell-based backdoor that can download and run additional payloads, and KEYBOUNCER, a keylogger that can record keystrokes and screenshots. The organisation also makes use of freely accessible technologies that facilitate lateral movement and privilege escalation, including PsExec and Mimikatz. The study reveals a number of new tools and strategies employed by MuddyWater. One of these is a brand-new POWRUNER-based PowerShell downloader that is used to retrieve and run additional payloads from the group's C&C servers. Another is the storage and spread of stolen data via cloud storage services like Dropbox and Google Drive. Researchers also point out that MuddyWater has recently been seen focusing on financial sector firms. The organisation has been employing a brand-new backdoor, known as BLACKOUT, that can steal banking passwords and carry out other harmful activities.
The analysis of the researcher offers a thorough overview of MuddyWater's TTPs and infrastructure, which could help organisations in defending against the group's attacks. Strong email security measures, such as anti-phishing software and employee training, are essential. The research also points out the need for outbound traffic monitoring and blocking against known-bad IP addresses and domains.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/04/iranian-hackers-using-simplehelp-remote.html
[/emaillocker]