Since early 2025, cybersecurity teams have observed a notable resurgence in operations attributed to MuddyWater, an Iranian state-backed advanced persistent threat (APT). The group, which initially emerged through broad remote monitoring and management (RMM) exploits, has shifted to highly targeted campaigns using custom malicious backdoors and multi-layered payloads designed to evade detection.
See also: New FileFix variant distributes StealC malware

Rather than relying solely on off-the-shelf tools, attackers have expanded their arsenal to include custom implants such as BugSleep, StealthCache , and the Phoenix backdoor. These components work in conjunction to create hidden bases, extract sensitive data , and cloak infrastructure using commercial services at scale.
Attack paths continue to focus on spear-phishing emails that embed malicious Microsoft Office. Victims receive decoy documents, loaded with VBA macros that drop and execute secondary payloads from Cloudflare-protected domains. Infected computers then communicate with command and control (C2) servers hosted on mainstream and bulletproof providers—from AWS and DigitalOcean to Stark Industries—before routing the communication behind Cloudflare proxies to mask the originating IPs.
See also: Sidewinder APT exploits protests in Nepal to distribute malware

Analysts noted that Cloudflare’s reverse proxy service dramatically increases the difficulty of monitoring active C2 endpoints, as all traffic appears to originate from Cloudflare’s shared hosts. When executed, the initial loader (usually named wtsapi32.dll) decrypts and injects the StealthCache backdoor into legitimate processes. StealthCache creates a pseudo-protocol TLV over HTTPS, sending and receiving encrypted commands to the /aq36 endpoint and reporting errors to /q2qq32. Analysts identified custom XOR routines that dynamically generate decryption keys from victims’ devices and username strings, preventing sandbox analysis when executed on mismatched hosts.
In its latest phase of operation, MuddyWater's multi-layered approach has delivered a trio of payloads: an initial VBA dropper, a loader like Fooder, and a feature-rich backdoor like StealthCache. Upon receiving a command code, StealthCache performs actions ranging from interactive shells to file extraction. The Phoenix backdoor is then deployed from the loader's memory space. Phoenix registers with its C2 via /register and then periodically sends beacons to /imalive and checks /request for further instructions. This modular design allows for seamless command updates and payload swapping without writing to disk, enhancing persistence and minimizing forensic evidence.
See also: Docker malware targets exposed APIs

By using Cloudflare to mask the actual server endpoints and incorporating dynamic decryption locked to host identifiers, MuddyWater has created a resilient, multi-layered infection chain that remains invisible to network defenders. Continuous monitoring of Cloudflare-related domains, alongside vigilant analysis of unique mutex names and C2 URL patterns, is essential to prevent new campaigns and protect critical infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
