The Iranian state-run MuddyWater group has been linked to a new campaign that exploited a compromised email account to distribute a backdoor called Phoenix, targeting various organizations in the Middle East and North Africa (MENA), including 100+ government entities.

The ultimate goal of the campaign is to infiltrate high-value targets and facilitate intelligence collection, according to cybersecurity firm Group-IB.
More than three-quarters of the campaign's targets include embassies, diplomatic missions, foreign ministries and consulates, followed by international organizations and telecommunications companies.
See also: Google 'Careers' scam traps prospective employees
“ MuddyWater gained access to the compromised Inbox via NordVPN (a legitimate service that the attacker abused) and used it to send phishing emails that appeared to be genuine mail ,” security researchers Mahmoud Zohdy and Mansour Alhmoud said . “ By exploiting the trust and authority associated with such communications, the campaign significantly increased the chances of tricking recipients into opening the malicious attachments .”
The attack chain involves distributing infected Microsoft Word that, when opened, prompt email recipients to enable macros to view the content. Once the unsuspecting user enables the feature, the document executes malicious Visual Basic for Application (VBA) code, resulting in the deployment of version 4 of the Phoenix.

The backdoor is launched via a loader called FakeUpdate, which is decoded and written to disk by the VBA dropper. The loader contains the Phoenix payload encrypted with Advanced Encryption Standard (AES).
See also: Sharepoint: Chinese target organizations via ToolShell vulnerability
Iranian hackers MuddyWater
MuddyWater, also known as Boggy Serpens, Cobalt Ulster, Earth Vetala, Mango Sandstorm (formerly Mercury), Seedworm, Static Kitten, TA450, TEMP.Zagros, and Yellow Nix, is believed to be linked to Iran’s Ministry of Intelligence and Security (MOIS). It has been active since at least 2017.
The group's use of Phoenix was first documented by Group-IB last month, describing it as a lightweight version of BugSleep, a Python-based implant associated with MuddyWater. Two different variants of Phoenix (Version 3 and Version 4) have been detected in the environment.
The cybersecurity vendor noted that the attacker's command and control (C2) server (“159.198.36[.]115”) has also been found to host remote monitoring and management (RMM) tools and a custom credential stealer for browsers (such as Brave, Google Chrome, Microsoft Edge, and Opera), indicating their potential use in the enterprise.
See also: Azure: How hackers imitated Microsoft apps and tricked users

MuddyWater has a history of distributing remote access software via phishing campaigns. “By deploying updated malware variants such as the Phoenix v4 backdoor, FakeUpdate injector, and custom credential stealing tools alongside legitimate RMM tools such as PDQ and Action1, MuddyWater has demonstrated an increased ability to integrate custom code with commercial tools for improved concealment and persistence,” the researchers said.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
