Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign

Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign

MuddyWater, an Iranian state-sponsored group, has launched a campaign targeting organizations across the MENA region using phishing emails and the Phoenix backdoor. The campaign aims to gather intelligence from diplomatic missions, government agencies, and international organizations. #MuddyWater #PhoenixBackdoor

Keypoints

  • MuddyWater exploited a compromised email account to distribute the Phoenix backdoor.
  • The campaign primarily targets embassies, diplomatic missions, and government agencies in the MENA region.
  • Phishing emails contained weaponized Microsoft Word documents that deploy the Phoenix backdoor when macros are enabled.
  • The threat actor uses legitimate services like NordVPN to mask their activities and enhance deception.
  • MuddyWater employs various tools, including RMM utilities and credential stealers, to maintain stealth and persistence.

Read More: https://thehackernews.com/2025/10/iran-linked-muddywater-targets-100.html