Ravie LakshmananOct 22, 2025Malware / Cyber Espionage
The top aim of the marketing campaign is to infiltrate high-value targets and facilitate intelligence gathering, Singaporean cybersecurity firm Group-IB mentioned in a technical report printed in the present day.
Greater than three-fourths of the marketing campaign’s targets embody embassies, diplomatic missions, overseas affairs ministries, and consulates, adopted by worldwide organizations and telecommunications corporations.
“By exploiting the trust and authority associated with such communications, the campaign significantly increased its chances of deceiving recipients into opening the malicious attachments.”
The backdoor is launched by way of a loader referred to as FakeUpdate that is decoded and written to disk by the VBA dropper. The loader accommodates the Superior Encryption Commonplace (AES)-encrypted Phoenix payload.

MuddyWater, additionally referred to as Boggy Serpens, Cobalt Ulster, Earth Vetala, Mango Sandstorm (previously Mercury), Seedworm, Static Kitten, TA450, TEMP.Zagros, and Yellow Nix, is assessed to be affiliated with Iran’s Ministry of Intelligence and Safety (MOIS). It is identified to be lively since a minimum of 2017.
The risk actor’s use of Phoenix was first documented by Group-IB final month, describing it as a light-weight model of BugSleep, a Python-based implant linked to MuddyWater. Two totally different variants of Phoenix (Model 3 and Model 4) have been detected within the wild, providing capabilities to assemble system data, set up persistence, launch an interactive shell, and add/obtain information.
The cybersecurity vendor mentioned the attacker’s command-and-control (C2) server (“159.198.36[.]115”) has additionally been discovered internet hosting distant monitoring and administration (RMM) utilities and a customized internet browser credential stealer that targets Courageous, Google Chrome, Microsoft Edge, and Opera, suggesting their doubtless use within the operation. It is price noting that MuddyWater has a historical past of distributing distant entry software program by way of phishing campaigns over time.
“By deploying updated malware variants such as the Phoenix v4 backdoor, the FakeUpdate injector, and custom credential-stealing tools alongside legitimate RMM utilities like PDQ and Action1, MuddyWater demonstrated an enhanced ability to integrate custom code with commercial tools for improved stealth and persistence,” the researchers mentioned.

