MuddyWater__2018__MuddyWater_Middle_East_and_Central_Asia.pdf
ID: 9801241d-fc11-4146-81d6-eb7e80fc0e67
STIX ID: report--9801241d-fc11-4146-81d6-eb7e80fc0e67
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2018-03-15
Last Modified Date: 2018-03-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro describes a targeted cyber-espionage campaign, potentially connected to the MuddyWater group, that uses macro-laced lure documents to deliver an obfuscated Visual Basic script and PowerShell backdoor targeting government and telecom entities in Turkey, Pakistan and Tajikistan; the backdoor collects system info and screenshots, communicates with C2 via hacked proxy websites using a homegrown RSA-like scheme, supports commands including data exfiltration and a destructive 'clean' drive-wipe, and the report includes detailed IOCs (hashes, URLs) and mitigation guidance.
