logo

MuddyWater expands operations

ID: c7616059-de4b-4450-8de0-e7f0e31d4038

STIX ID: report--c7616059-de4b-4450-8de0-e7f0e31d4038

Threat Score

82/100

Uploaded: 2026-08-19

Published Date: 2018-10-16

Last Modified Date: 2018-10-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky researchers describe an ongoing 2018 MuddyWater APT campaign using macro-enabled Word spear-phishing documents targeting government, military, telecom and education entities across the Middle East, Europe and the US; the macros drop obfuscated PowerShell-based backdoors that disable Office protections, establish C2 via a list of URLs, perform reconnaissance, support remote commands (screenshot, upload, execute scripts, destructive 'clean'), and employ persistence and anti-analysis techniques. The report provides detailed execution flows, IoCs (MD5s, filenames, domains, IPs), OPSEC artefacts suggesting possible operator usernames, and concrete mitigation recommendations.