logo

MuddyWater__2023__Symantec_Seedworm-Iranian-Hackers-Target-Telecoms-Orgs-North-East-Africa_12-19-2023.pdf

ID: a1156d4b-f21c-4136-8619-d6e18e015c19

STIX ID: report--a1156d4b-f21c-4136-8619-d6e18e015c19

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2023-12-20

Last Modified Date: 2023-12-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Seedworm (aka MuddyWater), an Iran-linked APT, conducted a November 2023 cyber-espionage campaign targeting telecommunications organizations in Egypt, Sudan, and Tanzania; attackers used a mix of custom and publicly available tools — notably the MuddyC2Go Go-based framework (sideloaded via jabswitch.exe), SimpleHelp, a custom Venom Proxy build, Revsocks, AnyDesk, PowerShell stagers, and a custom keylogger — to establish persistence and remote access. Symantec’s report details the attack chain, examples of PowerShell C2 stagers, scheduled task execution, and provides file and network IOCs (hashes and C2 IPs) along with mitigation guidance.