New Malware Alert: MuddyWater Shifts Tactics with BugSleep Backdoor

The Iranian nation-state actor MuddyWater has ditched its usual remote monitoring tools for a custom backdoor called BugSleep. This shift in tactics highlights their persistent phishing campaigns and evolving techniques, particularly targeting the Middle East.

Hot Take:

MuddyWater is like that one persistent ex who keeps finding new ways to slide into your DMs, but instead of awkward small talk, they’re bringing custom malware to the party. You’ve got to admire their creativity, but seriously, get a life!

Key Points:

  • MuddyWater shifts from its usual RMM software to a new backdoor named BugSleep or MuddyRot.
  • Targets include countries like Turkey, Azerbaijan, Jordan, Saudi Arabia, Israel, and Portugal.
  • MuddyWater is affiliated with Iran’s Ministry of Intelligence and Security (MOIS).
  • New implant capabilities include downloading/uploading files, launching a reverse shell, and setting up persistence.
  • The switch to a custom implant may be due to increased monitoring of RMM tools by security vendors.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here