logo

MuddyWater__2018__MuddyWater-Operations-in-Lebanon-and-Oman.pdf

ID: e2c60fd8-b02a-4a9d-892f-dfc60bb6651a

STIX ID: report--e2c60fd8-b02a-4a9d-892f-dfc60bb6651a

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2018-11-28

Last Modified Date: 2018-11-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**MuddyWater Operations in Lebanon and Oman:** ClearSky details a two-stage spear-phishing campaign by the MuddyWater APT that uses macro-embedded Word documents to spawn an Excel COM process which downloads obfuscated PowerShell hosted on compromised domains (including an Israeli domain) and executes a three-step chain (VBE → JavaScript → PowerShell) to install the POWERSTATS backdoor; the report includes technical deobfuscation, persistence findings (scheduled task / Run key), and IOCs for detection and mitigation.