MuddyWater__2018__MuddyWater-Operations-in-Lebanon-and-Oman.pdf
ID: e2c60fd8-b02a-4a9d-892f-dfc60bb6651a
STIX ID: report--e2c60fd8-b02a-4a9d-892f-dfc60bb6651a
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2018-11-28
Last Modified Date: 2018-11-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**MuddyWater Operations in Lebanon and Oman:** ClearSky details a two-stage spear-phishing campaign by the MuddyWater APT that uses macro-embedded Word documents to spawn an Excel COM process which downloads obfuscated PowerShell hosted on compromised domains (including an Israeli domain) and executes a three-step chain (VBE → JavaScript → PowerShell) to install the POWERSTATS backdoor; the report includes technical deobfuscation, persistence findings (scheduled task / Run key), and IOCs for detection and mitigation.
