Threat Actor 🇮🇷 Iran
MuddyWater
Also known as: TEMP.Zagros · Static Kitten · Seedworm · MERCURY · COBALT ULSTER · G0069 · ATK51 · Boggy Serpens · Mango Sandstorm · TA450 · Earth Vetala
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.
Indicators of Compromise 45
Domain cloudlanecdn[.]com Domain corp-connect[.]top Domain hospitalinstallation[[.]]com Domain is-01-ast[.]ols-img-12[.]workers[.]dev Domain scan-security[.]top Domain sendit[.]sh Domain sequrityupdate[.]top Domain studiotikva[.]com Domain supportsoft[.]top Domain svc[.]wompworthy[.]com Domain system-connect[.]top Domain timetrakr[.]cloud Filename a.dat Filename a.exe Filename db.dll Filename fmapp.dll Filename fmapp.exe Filename logAzure.txt Filename lpu.dll Filename mhm.dll Filename n-HTCommp.dll Filename n-sws.dll Filename n-ten.dll Filename nm.ps1 Filename ode.dll Filename readme.chaos.txt Filename sentinelagentcore.dll Filename sentinelmemoryscanner.exe Filename sp.ps1 Filename uxtheme.dll SHA-256 0c9b911935a3705b0ad569446804d80026feb6db3884aeb240b6c76e9b8cf139 SHA-256 128b58a2a2f1df66c474094aacb7e50189025fbf45d7cd8e0834e93a8fbed667 SHA-256 3ee7dab4ae4f6d4f16dfabb6f38faef370411a9fc00ff035844e54703b99600a SHA-256 6182fd01b14d84723e3c9d11bc0e16b34de6607ccb8334fc9bb97c1b44f0cde SHA-256 74ab3838ebed7054b2254bf7d334c80c8b2cfec4a97d1706723f8ea55f11061f SHA-256 b21c802775df0c0d82c8cfde299084abc624898b10258db641b820172a0ba29a SHA-256 bee79c3302b1a7afc0952842d14eff83a604ef00bfdae525176c16c80b2045f7 SHA-256 d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc SHA-256 e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b IP 104[.]21[.]48[.]205 IP 172[.]67[.]156[.]47 IP 178[.]128[.]233[.]36 IP 179[.]43[.]177[.]220 IP 34[.]117[.]59[.]81 IP 37[.]187[.]78[.]41
MITRE ATT&CK TTPs 32
T1001.002 T1003 T1003.002 T1021.001 T1021.003 T1027 T1055.001 T1059 T1059.001 T1059.007 T1068 T1071.001 T1071.004 T1074 T1074.001 T1082 T1085 T1090 T1090.003 T1105 T1132.001 T1204.002 T1219 T1486 T1543.003 T1557.001 T1558.003 T1566 T1566.002 T1573.001 T1574.002 T1588
Steganography
Command And Control
OS Credential Dumping
Credential Access
Security Account Manager
Credential Access
Remote Desktop Protocol
Lateral Movement
Distributed Component Object Model
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Dynamic-link Library Injection
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
JavaScript
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Web Protocols
Command And Control
DNS
Command And Control
Data Staged
Collection
Local Data Staging
Collection
System Information Discovery
Discovery
T1085
Proxy
Command And Control
Multi-hop Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Standard Encoding
Command And Control
Malicious File
Execution
Remote Access Software
Command And Control
Data Encrypted for Impact
Impact
Windows Service
Persistence
LLMNR/NBT-NS Poisoning and SMB Relay
Credential Access
Kerberoasting
Credential Access
Phishing
Initial Access
Spearphishing Link
Initial Access
Symmetric Cryptography
Command And Control
DLL Side-Loading
Persistence
Obtain Capabilities
Resource Development
Source Articles
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Iranian nation-state actors linked to Cavern (aka Cav3rn) C2 framework have evolved their infrastructure to blend malicious traffic with legitimate services, using DNS A-record queries to dynamically switch between direct HTTPS and Google Apps Script relays for command-and-control. A new module, HOLLOWGRAPH, abuses Microsoft 365 calendars via the Graph API to exfiltrate data and receive commands, with events scheduled far into the future to avoid detection. The framework uses a modular architecture with components like GoogleService.dll and rnp.dll, leveraging legitimate cloud services to evade perimeter defenses and maintain persistence.
hacker-news ·2w ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
Iran-linked threat actor Seedworm (also known as MuddyWater, Temp Zagros, Static Kitten) conducted a global espionage campaign in early 2026, breaching at least nine organizations across four continents, including a major South Korean electronics manufacturer. The attackers used DLL sideloading with legitimately signed binaries from Fortemedia and SentinelOne to execute malicious payloads, leveraging Node.js scripts to orchestrate PowerShell-based reconnaissance, credential theft, privilege escalation, and SOCKS5 reverse-proxy tunneling. Data exfiltration was performed via the public file-transfer service sendit[.]sh, blending malicious traffic with legitimate cloud services to evade detection. The campaign reflects an evolution in Seedworm’s tradecraft toward more disciplined and stealthy operations.
security-com ·3mo ago
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are conducting vishing attacks via Microsoft Teams, impersonating IT support staff to trick employees into granting remote access to corporate devices. These intrusions are part of campaign STAC4749, tracked by Sophos, which led to the deployment of Chaos ransomware in at least three organizations. The attackers used fake IT-themed domains and spoofed identities to initiate contact, then deployed remote management tools like RemSupp and PowerShell-based backdoors to establish persistence and move laterally. The campaign targeted primarily North American organizations, with attacks spanning from February to June 2026, and demonstrated rapid progression from initial access to ransomware encryption—sometimes within 17 hours.
bleeping-computer ·4w ago
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is deploying a new Rust-based backdoor named msaRAT that leverages Chrome or Edge browsers to route command-and-control (C2) traffic, evading detection by avoiding direct network connections. The malware uses the Chrome DevTools Protocol to control a headless browser session and establishes encrypted communication via WebRTC through Twilio TURN servers and a Cloudflare Workers endpoint. This dual-layer infrastructure hides the attacker's true C2 server and complicates traceback efforts, while also bypassing firewalls and allowlists by blending with legitimate web traffic.
bleeping-computer ·1mo ago
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.
hacker-news ·1mo ago
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group linked to the Ministry of Intelligence and Security (MOIS), tracked as Cavern Manticore, has been using a new modular command-and-control (C2) framework named Cavern to target Israeli organizations, particularly in the IT and government sectors. The attack leverages DLL side-loading via SysAid's software update mechanism, deploying a trojanized DLL (uxtheme.dll) that communicates with a C2 server and downloads additional malicious modules. These modules enable reconnaissance, data theft, lateral movement, and tunneling, with a sophisticated .NET-based architecture using mixed compilation formats to hinder analysis. The group exploits trusted relationships in the software supply chain and has shifted from broad reconnaissance to targeted data exfiltration across Middle Eastern sectors.
hacker-news ·1mo ago