As reported by The Hacker News, the Iranian threat actor known as MuddyWater has been linked to a sophisticated spear-phishing campaign. This campaign is actively targeting critical entities across the Middle East, employing a newly identified Rust-based implant dubbed RustyWater.The campaign leverages icon spoofing and malicious Microsoft Word documents to deploy the RustyWater implant. This malware is designed with advanced capabilities, including asynchronous command and control (C2), anti-analysis techniques, registry persistence, and modular expansion for post-compromise activities. Attackers send spear-phishing emails disguised as cybersecurity guidelines, which contain a Word document. Upon opening, victims are prompted to "Enable content," triggering a malicious VBA macro that deploys the Rust implant.RustyWater gathers system information, detects security software, establishes persistence via the Windows Registry, and communicates with a C2 server at "nomercys.it[.]com" for file operations and command execution. Entities targeted include those belonging to the diplomatic, maritime, financial, and telecommunications sectors.The adoption of Rust-based implants by MuddyWater signifies a notable evolution in their tradecraft, moving away from traditional tools towards more structured, modular, and stealthy remote access trojan (RAT) capabilities.Source: The Hacker News
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
