The MuddyWater APT Group Adds New Tools to Their Arsenal
#1
Quote:The Iranian MuddyWater cyber-espionage group added new attack vectors to use as part of hacking campaigns targeting telecommunication and governmental organizations according to an analysis from the Clearsky Security threat intelligence outfit.
 
This happened despite the advanced persistent threat (APT) group — or government-backed hacking group — having screenshots of their server backends and one of their command-and-control (C2) server's codebase leaked via a Telegram channel during early-May. 
 
MuddyWatter actors have supplemented their tactics, techniques, and procedures (TTPs) with new decoy macro-powered Microsoft Word documents that drop payloads via compromised servers and new documents designed to leverage the tried-and-true CVE-2017-0199 also known as Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API.
 
The documents which deliver VBA macros to the targets' computers will download a second stage malware payload camouflaged as JPG files from hacked servers located in the same countries as the potential victims. 

The ones designed to exploit CVE-2017-0199 "were identified by only three antivirus engines. This is in stark comparison to a previous attack we reported on, in which the documents were identified 32 times," says the Clearsky Security report.

SOURCE: https://www.bleepingcomputer.com/news/se...r-arsenal/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
The MuddyWater APT Group Adds New Tools to Their Arsenal - by silversurfer - 06 June 19, 12:59

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AxCrypt 3.1.5.0
AxCrypt 3.1.5.0: ...harlan4096 — 11:50
AMD will reinstate memory encryption on ...
The feature was qu...harlan4096 — 11:48
Microsoft confirms Windows 11 version 26...
Who would have gue...harlan4096 — 11:46
Windows 11 June 2026 Update Breaks Recyc...
Microsoft has conf...harlan4096 — 11:45
Microsoft Edge 149.0.4022.80
Release Summary ...harlan4096 — 15:38

[-]
Birthdays
Today's Birthdays
avatar (48)kinotHeemn
avatar (39)Ceballos1976
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>