Saturday, August 15, 2026
LIVE
Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///
Subscribe
Africa
Independent · Digital
The African Herald
PoliticsAI-assisted

MuddyWater Attacks Critical Infrastructure With Custom Malware and Improved Tactics

MuddyWater, a cyberespionage group aligned with Iran and also known as Mango Sandstorm, has initiated a targeted campaign against critical infrastructure in Israel and Egypt.

MuddyWater, a cyberespionage group aligned with Iran and also known as Mango Sandstorm, has initiated a targeted campaign against critical infrastructure in Israel and Egypt.

The campaign, active from September 2024 through March 2025, focuses on sectors such as engineering, utilities, local government, and technology.

This operation signifies an evolution in MuddyWater's approach, transitioning from noisy attacks to a refined methodology that integrates custom-built malware with advanced evasion tactics. This strategy is designed to maintain long-term access without alerting defenders.

The initial infection vector uses spearphishing, where victims receive emails containing links to installers for Remote Monitoring and Management (RMM) software like Atera, Syncro, and PDQ, hosted on free file-sharing services to avoid detection.

Once compromised, the attackers deploy a sophisticated toolset to steal credentials and exfiltrate sensitive browser data while avoiding interactive sessions that trigger alarms.

MuddyWater, a cyberespionage group aligned with Iran and also known as Mango Sandstorm, has initiated a targeted campaign against critical infrastructure in Israel and Egypt.
Amara Diallo · The African Herald

Security analysts identified previously undocumented tools in this campaign, specifically the "Fooder" loader and "MuddyViper" backdoor. These components employ the Windows CNG cryptographic API, a feature not commonly observed in Iran-linked groups.

The malware disguises itself as harmless applications, utilizing complex loading chains to execute payloads.

The Fooder Loader and MuddyViper Mechanics

The Fooder loader is a custom C++ executable that loads the MuddyViper backdoor directly into memory. It masquerades as the classic "Snake" video game, using game logic in its evasion routines. The loader utilizes a custom delay function alongside Sleep API calls to bypass automated sandbox analysis.

Advertisement

Upon execution, Fooder decrypts its payload with a hardcoded AES key. MuddyViper then operates entirely in memory, generating status logs to signal its activation. It establishes persistence via registry keys or scheduled tasks and communicates with command and control servers using encrypted traffic.

The backdoor also uses social engineering tactics by displaying fake login prompts to collect user credentials. This combination of obfuscation and spyware capabilities represents an upgrade in MuddyWater's operational toolkit.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories