MuddyWater__2023__Symantec_Seedworm-Iranian-Hackers-Target-Telecoms-Orgs-North-East-Africa_12-19-2023.pdf
ID: a1156d4b-f21c-4136-8619-d6e18e015c19
STIX ID: report--a1156d4b-f21c-4136-8619-d6e18e015c19
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2023-12-20
Last Modified Date: 2023-12-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Seedworm (aka MuddyWater), an Iran-linked APT, conducted a November 2023 cyber-espionage campaign targeting telecommunications organizations in Egypt, Sudan, and Tanzania; attackers used a mix of custom and publicly available tools — notably the MuddyC2Go Go-based framework (sideloaded via jabswitch.exe), SimpleHelp, a custom Venom Proxy build, Revsocks, AnyDesk, PowerShell stagers, and a custom keylogger — to establish persistence and remote access. Symantec’s report details the attack chain, examples of PowerShell C2 stagers, scheduled task execution, and provides file and network IOCs (hashes and C2 IPs) along with mitigation guidance.
