MuddyWater Attacks Critical Infrastructure With Custom Malware and Improved Tactics
MuddyWater, a cyberespionage group aligned with Iran and also known as Mango Sandstorm, has initiated a targeted campaign against critical infrastructure in Israel and Egypt.
MuddyWater, a cyberespionage group aligned with Iran and also known as Mango Sandstorm, has initiated a targeted campaign against critical infrastructure in Israel and Egypt.
The campaign, active from September 2024 through March 2025, focuses on sectors such as engineering, utilities, local government, and technology.
This operation signifies an evolution in MuddyWater's approach, transitioning from noisy attacks to a refined methodology that integrates custom-built malware with advanced evasion tactics. This strategy is designed to maintain long-term access without alerting defenders.
The initial infection vector uses spearphishing, where victims receive emails containing links to installers for Remote Monitoring and Management (RMM) software like Atera, Syncro, and PDQ, hosted on free file-sharing services to avoid detection.
Once compromised, the attackers deploy a sophisticated toolset to steal credentials and exfiltrate sensitive browser data while avoiding interactive sessions that trigger alarms.
MuddyWater, a cyberespionage group aligned with Iran and also known as Mango Sandstorm, has initiated a targeted campaign against critical infrastructure in Israel and Egypt.
Security analysts identified previously undocumented tools in this campaign, specifically the "Fooder" loader and "MuddyViper" backdoor. These components employ the Windows CNG cryptographic API, a feature not commonly observed in Iran-linked groups.
The malware disguises itself as harmless applications, utilizing complex loading chains to execute payloads.
The Fooder Loader and MuddyViper Mechanics
The Fooder loader is a custom C++ executable that loads the MuddyViper backdoor directly into memory. It masquerades as the classic "Snake" video game, using game logic in its evasion routines. The loader utilizes a custom delay function alongside Sleep API calls to bypass automated sandbox analysis.
Upon execution, Fooder decrypts its payload with a hardcoded AES key. MuddyViper then operates entirely in memory, generating status logs to signal its activation. It establishes persistence via registry keys or scheduled tasks and communicates with command and control servers using encrypted traffic.
The backdoor also uses social engineering tactics by displaying fake login prompts to collect user credentials. This combination of obfuscation and spyware capabilities represents an upgrade in MuddyWater's operational toolkit.
Based on reporting by Cyber Security News.



