logo

MuddyWater__2018__MuddyWater_Middle_East_and_Central_Asia.pdf

ID: 9801241d-fc11-4146-81d6-eb7e80fc0e67

STIX ID: report--9801241d-fc11-4146-81d6-eb7e80fc0e67

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2018-03-15

Last Modified Date: 2018-03-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro describes a targeted cyber-espionage campaign, potentially connected to the MuddyWater group, that uses macro-laced lure documents to deliver an obfuscated Visual Basic script and PowerShell backdoor targeting government and telecom entities in Turkey, Pakistan and Tajikistan; the backdoor collects system info and screenshots, communicates with C2 via hacked proxy websites using a homegrown RSA-like scheme, supports commands including data exfiltration and a destructive 'clean' drive-wipe, and the report includes detailed IOCs (hashes, URLs) and mitigation guidance.