HomeSecurityMuddyWatter: Iranian hackers use new malware and target critical infrastructure

MuddyWatter: Iranian hackers are using new malware and targeting critical infrastructure

Cybersecurity agencies and law enforcement authorities in the US and UK are warning of new malware developed by the Iranian hacking group MuddyWatter and targeting critical infrastructure around the world.

MuddyWatter Iranian hacking group

This was revealed through a joint statement issued by CISA, FBI, CNMF, NCSC-UK, and NSA.

See also: New data-wiping malware targets networks in Ukraine

The Iranian government-backed group “ targets a range of government and private organizations across sectors – including telecommunications, defense, local government, and oil and gas – in Asia, Africa, Europe, and North America ,” the US and UK governments said

MuddyWater appears to be using a variety of malware to target critical infrastructure: PowGoop, Canopy/Starwhale, Mori, POWERSTATS, as well as other previously unknown malware. After using these malware, it then deploys second-stage malware on compromised systems, allowing backdoor access, persistence, and data theft.

See also: Ransomware attacks: The nightmare doesn't stop after the ransom is paid

critical infrastructure

Two of the malware analyzed by US and UK cybersecurity agencies were a new Python backdoor (named Small Sieve) used by the MuddyWater group for persistence and a PowerShell backdoor used to encrypt command-and-control (C2) communication channels.

MuddyWatter: Iranian intelligence hackers

The MuddyWatter cyberespionage group (also known as Earth Vetala, MERCURY, Static Kitten, Seedworm, and TEMP.Zagros) has been active since at least 2017. It typically targets Middle Eastern entities and is constantly upgrading the malware it uses.

The threat group is relatively new but is very active and targets telecommunications organizations, government agencies, and energy organizations.

See also: An ongoing phishing campaign targets Citibank customers

Recently, it has also targeted government and defense entities in Central and Southwest Asia, as well as private and public organizations from North America, Europe, and Asia.

In January 2022, MuddyWatter was officially linked to Iran's Ministry of Intelligence and Security (MOIS), by the US Cyber ​​Command (USCYBERCOM).

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS