Rewterz Threat Alert – MuddyWater APT Group – Active IOCs
Severity
High
Analysis Summary
The Iranian cybercriminal group MuddyWater has resurfaced. The group primarily has targeted Middle Eastern, European, and North American nations. The industries under target include telecommunications, government (IT services), and oil sectors. Most of the campaigns by MuddyWater are designed upon socially engineering their victims into enabling macros in order to infect the targeted workstation. Once macros were enabled, the threat actor-written code would attempt to obtain a trojan hosted on an adversarial payload command and control node.