The Iranian-backed hacking group MuddyWatterhas partially turned to using its new custom BugSleep malwareto steal files and execute commands on compromised systems.
See also: BeaverTail: New version of macOS malware discovered

Dubbed BugSleep, this new malware is still actively being developed and was discovered by analysts at Check Point Research, while being distributed through well-crafted phishing.
The campaign pushes the malware through phishing emails disguised as invitations to webinars or online courses. The emails redirect targets to files containing malicious payloads, hosted on the secure file-sharing platform Egnyte.
Some versions also come with a custom malware loader designed to inject it into the active processes of certain applications, including Microsoft Edge, Google Chrome, AnyDesk, Microsoft OneDrive, PowerShell , and Opera.
“ We discovered several versions of the BugSleep malware being distributed, with differences between each version suggesting improvements and bug fixes (and sometimes introducing new bugs) ,” Check Point said . “ These updates, occurring at short intervals between samples, suggest a trial-and-error approach .”
By switching to BugSleep, the MuddyWatter team switched from exclusively using legitimate Remote Management Tools (RMM) like Atera Agent and Screen Connect to maintain access to victims' networks.
See also: Malicious Facebook ads distribute info-stealing malware

Attacks using the new BugSleep malware are focused on a wide range of targets worldwide, from government organizations and municipalities to airlines and media outlets, with targets in Israel and some in Turkey, Saudi Arabia, India and Portugal.
MuddyWatter (also known as Earth Vetala, MERCURY, Static Kitten, and Seedworm), first appeared in 2017.It is known to primarily target Middle Eastern entities (with a focus on Israeli targets) and is constantly upgrading its arsenal.
Although relatively new compared to other state-backed hacking, this Iranian threat group is particularly active and targets multiple industry sectors, including telecommunications, government (IT services) , and oil industry organizations.
Since its emergence, it has slowly expanded its attacks into cyberespionage campaigns against government and defense entities in Central and Southwest Asia, as well as organizations from North America, Europe, and Asia.
See also: Ukrainian hacker sentenced to prison for his involvement in Zeus and IcedID malware
Malware, like BugSleep, is a term that encompasses various types of malicious software designed to disrupt, damage, or gain unauthorized access to systems and networks. Common forms of malware include viruses, worms, Trojans, ransomware , and spyware. Each type operates differently, but their primary goal is to compromise the integrity and security of the targeted system. The spread of malware poses significant threats to both personal and organizational data, requiring strong cybersecurity measures and practices to prevent and mitigate potential damage.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
