MuddyWater Targets Critical Infrastructure With Custom Malware and Evolving Tactics
## Cybersecurity: MuddyWater Campaign Analysis
Cybersecurity: MuddyWater Campaign Analysis
ESET researchers have identified a sophisticated campaign by MuddyWater, an Iran-aligned cyber-espionage group, targeting critical infrastructure in the Middle East. This campaign demonstrates significant operational evolution with a newly refined toolkit.
Conducted from September 2024 to March 2025, the campaign primarily focused on organizations in Israel, with one confirmed victim in Egypt. This marks a shift from the group's historically detectable operations.
The campaign features previously undocumented custom tools designed to enhance defense evasion and persistence capabilities. The Fooder loader, a 64-bit C/C++ tool, represents a notable technological advancement. Some variants mimic the classic Snake game, incorporating its mechanics as an evasion technique.
The loader uses custom delay functions and Sleep API calls to slow execution, evading automated malware analysis systems. Its primary function involves reflectively loading the MuddyViper backdoor into memory without writing to disk.
MuddyViper, a newly identified C/C++ backdoor, offers comprehensive command and control capabilities, including system reconnaissance, credential harvesting, file operations, and shell command execution. It supports 20 distinct commands for reverse shell operations, browser data exfiltration, and fake credential prompts.
ESET researchers have identified a sophisticated campaign by MuddyWater, an Iran-aligned cyber-espionage group, targeting critical infrastructure in the Middle East.
The campaign adopts Microsoft's Cryptography Next Generation (CNG) API, marking the first known use of this modern encryption standard by Iran-aligned groups. Both MuddyViper and related data stealer variants utilize AES-CBC encryption via the CNG API.
The campaign also employs credential stealers, including CE-Notes and LP-Notes, targeting browser data and Windows credentials. CE-Notes specifically addresses app-bound encryption introduced in Chrome version 127.
The targeting strategy involves multiple critical sectors, with a focus on Israeli organizations, including engineering firms, local government entities, manufacturing companies, utilities, universities, and transportation infrastructure. This focus aligns with strategic geopolitical objectives.
ESET identified operational overlap between MuddyWater and Lyceum, an OilRig subgroup, in early 2025. MuddyWater conducted initial access via spearphishing emails with links to Syncro remote monitoring software. Following compromise, operators deployed additional RMM tools and custom Mimikatz loaders before transferring access to Lyceum.
This cooperation suggests MuddyWater may now function as an initial access broker for other Iran-aligned threat actors, fundamentally altering its operational model. Despite advancements, some operational immaturity remains, with verbose status messages and a hardcoded list of security tool process names generating substantial network traffic.
The campaign's evolution from easily detectable operations to increasingly refined attacks poses escalating challenges for defenders. ESET assesses that MuddyWater will continue as a leading actor in Iranian-nexus espionage activities, with campaigns enhanced by advanced techniques.
Organizations in government, telecommunications, and critical infrastructure sectors should prioritize monitoring for spearphishing emails containing RMM software links and implement detection for reflective loading techniques and credential theft activities.
Based on reporting by GBHackers.



