Clearsky-Iranian-APT-group-‘MuddyWater’-Adds-Exploits-to-Their-Arsenal.pdf
ID: acc5811e-e61e-4c8e-9e2d-502f84ff911d
STIX ID: report--acc5811e-e61e-4c8e-9e2d-502f84ff911d
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2019-06-06
Last Modified Date: 2019-06-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ClearSky's June 2019 intelligence report analyzes an active MuddyWater campaign that leverages malicious Microsoft Office documents—both VBA macro-based and CVE-2017-0199 exploits—to deliver a PowerShell-extracted RAT and maintain C2 communications; the report provides behavioural analysis, observed infection chains, compromised servers, and a set of IoCs (hashes, IPs, and malicious URLs) targeting governmental and telecommunications entities in the region.
