Cybersecurity agencies and law enforcement authorities in the US and UK are warning of new malware developed by the Iranian hacking group MuddyWatter and targeting critical infrastructure around the world.

This was revealed through a joint statement issued by CISA, FBI, CNMF, NCSC-UK, and NSA.
See also: New data-wiping malware targets networks in Ukraine
The Iranian government-backed group “ targets a range of government and private organizations across sectors – including telecommunications, defense, local government, and oil and gas – in Asia, Africa, Europe, and North America ,” the US and UK governments said
MuddyWater appears to be using a variety of malware to target critical infrastructure: PowGoop, Canopy/Starwhale, Mori, POWERSTATS, as well as other previously unknown malware. After using these malware, it then deploys second-stage malware on compromised systems, allowing backdoor access, persistence, and data theft.
See also: Ransomware attacks: The nightmare doesn't stop after the ransom is paid

Two of the malware analyzed by US and UK cybersecurity agencies were a new Python backdoor (named Small Sieve) used by the MuddyWater group for persistence and a PowerShell backdoor used to encrypt command-and-control (C2) communication channels.
MuddyWatter: Iranian intelligence hackers
The MuddyWatter cyberespionage group (also known as Earth Vetala, MERCURY, Static Kitten, Seedworm, and TEMP.Zagros) has been active since at least 2017. It typically targets Middle Eastern entities and is constantly upgrading the malware it uses.
The threat group is relatively new but is very active and targets telecommunications organizations, government agencies, and energy organizations.
See also: An ongoing phishing campaign targets Citibank customers
Recently, it has also targeted government and defense entities in Central and Southwest Asia, as well as private and public organizations from North America, Europe, and Asia.
In January 2022, MuddyWatter was officially linked to Iran's Ministry of Intelligence and Security (MOIS), by the US Cyber Command (USCYBERCOM).
Source: Bleeping Computer
