MuddyWater, an Iranian state-sponsored group, has launched a campaign targeting organizations across the MENA region using phishing emails and the Phoenix backdoor. The campaign aims to gather intelligence from diplomatic missions, government agencies, and international organizations. #MuddyWater #PhoenixBackdoor
Keypoints
- MuddyWater exploited a compromised email account to distribute the Phoenix backdoor.
- The campaign primarily targets embassies, diplomatic missions, and government agencies in the MENA region.
- Phishing emails contained weaponized Microsoft Word documents that deploy the Phoenix backdoor when macros are enabled.
- The threat actor uses legitimate services like NordVPN to mask their activities and enhance deception.
- MuddyWater employs various tools, including RMM utilities and credential stealers, to maintain stealth and persistence.
Read More: https://thehackernews.com/2025/10/iran-linked-muddywater-targets-100.html