logo

MuddyWater__2024__Seedworm_Iranian_Hackers_Target_Telecoms_Orgs_in_North_and_East_Africa_Symantec_Enterprise_Blogs.pdf

ID: 0f587c7b-e2db-4a7f-b2cd-068d7a0f33a0

STIX ID: report--0f587c7b-e2db-4a7f-b2cd-068d7a0f33a0

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2024-01-16

Last Modified Date: 2024-01-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec's Threat Hunter Team reports that the Iranian APT Seedworm conducted a November 2023 campaign against telecommunications organizations in Egypt, Sudan, and Tanzania using MuddyC2Go (a Go-based C2), SimpleHelp, Venom Proxy, AnyDesk, Revsocks and a custom keylogger. The attackers sideloaded a MuddyC2Go DLL via a Java executable, used scheduled tasks and WMI/Impacket tooling for execution, maintained persistence with remote access tools, and left multiple file and network IOCs (hashes and C2 IPs) for detection and mitigation.