Security researchers said they found evidence linking recent attacks Thanos ransomware.

Researchers at ClearSky and Profero were analyzing attacks on well-known Israeli organizations and discovered that the intrusions were linked to MuddyWater, a known hacking group funded by the Iranian government.
The researchers observed similar attack.
MuddyWater uses phishing emails with malicious Excel or PDF documents which, when opened, download and install malware from the hackers.
The group also scans the Internet for out-of-date Microsoft Exchange email servers, exploits the CVE-2020-0688 vulnerability, installs a web shell on the server, and finally downloads and installs the same malware distributed in phishing emails.
According to ClearSky, the final malware has only been observed once.
It's called PowGoop and it's a PowerShell-based threat that was first observed in early September and was used to install Thanos ransomware.
In a report shared with ZDNet, ClearSky said that researchers stopped the attacks before any damage was done. However, the company seems concerned about previous Thanos ransomware.
Security researchers believe that the state-sponsored hacking group MuddyWater had likely attempted to install Thanos ransomware as a means to hide its attacks and destroy evidence of the intrusionsby encrypting files on compromised networks.

The tactic of deploying ransomware to hide intrusions has been used again by other government-sponsored hackers
Previous Thanos ransomware attacks need to be reexamined. Was it a simple ransomware attack or was it linked to Iran's state-run hacking group?
The review of the attacks is very important because Thanos, which is offered as Ransomware-as-a-Service and is for rent on Russian-speaking hacking forums, is believed to be used by many cybercriminals.
ClearSky researcher Ohad Zaidenberg told ZDNet that he believes the MuddyWater ransomware attacks may be related to recent political tensions and cyberattacks between Iran and Israel.
MuddyWater is a state-sponsored hacking group with a history of many attacks. However, their previous attacks used more “stealth” techniques to gather information. Ransomware has nothing to do with these techniques, and it can also cause a lot of trouble for the victim.
