logo

MuddyWater__2019__MuddyC3.pdf

ID: 58ea7d98-28f0-4755-b648-685307b22af7

STIX ID: report--58ea7d98-28f0-4755-b648-685307b22af7

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2019-07-02

Last Modified Date: 2019-07-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Qianxin Threat Intelligence report analyzes the leaked MuddyC3 web-based C2 tool tied to the MuddyWater APT: researchers obtained source and samples (v1.0.0/1.0.1), decompiled PyInstaller-built Python code, mapped project structure and web endpoints, and documented macro-based initial payload delivery and C2 behavior; the leak and publicly posted samples (GitHub, Hybrid Analysis) indicate active tooling that supported spear-phishing campaigns against Middle Eastern targets.