logo

Clearsky-Iranian-APT-group-‘MuddyWater’-Adds-Exploits-to-Their-Arsenal.pdf

ID: acc5811e-e61e-4c8e-9e2d-502f84ff911d

STIX ID: report--acc5811e-e61e-4c8e-9e2d-502f84ff911d

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2019-06-06

Last Modified Date: 2019-06-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ClearSky's June 2019 intelligence report analyzes an active MuddyWater campaign that leverages malicious Microsoft Office documents—both VBA macro-based and CVE-2017-0199 exploits—to deliver a PowerShell-extracted RAT and maintain C2 communications; the report provides behavioural analysis, observed infection chains, compromised servers, and a set of IoCs (hashes, IPs, and malicious URLs) targeting governmental and telecommunications entities in the region.