Latest Campaign Sees Iranian MuddyWater Hackers Utilizing New C2 Tool ‘DarkBeatC2’

Published:

spot_img

Iranian Threat Actor MuddyWater Deploys New DarkBeatC2 Command-and-Control (C2) Infrastructure for Attacks

Iranian threat actor MuddyWater has recently been linked to a new command-and-control infrastructure dubbed DarkBeatC2, adding to its growing arsenal of tools for cyber attacks. This group, also known as Boggy Serpens, Mango Sandstorm, and TA450, is believed to be associated with Iran’s Ministry of Intelligence and Security (MOIS), with a history of spear-phishing attacks since 2017.

The latest attack campaign involves spear-phishing emails containing links or attachments hosted on services like Egnyte, leading to the deployment of Atera Agent software on compromised systems. It has been revealed that compromised email accounts from educational institutions in Israel, like Rashim, have been used to distribute these malicious links.

Furthermore, there are suspicions of collaboration between different Iranian threat activity clusters, such as MuddyWater and Storm-1084 (DarkBit), to execute destructive wiper attacks against Israeli entities. The connections between these groups have raised concerns about potential collaborations between MOIS and IRGC to maximize harm on Israeli organizations.

In another development, Iranian threat actor Peach Sandstorm has been using a backdoor called FalseFont to target the aerospace and defense sectors. This highly targeted backdoor tricks victims into installing malware by mimicking legitimate human resources software, capturing credentials and sensitive information.

Overall, these revelations highlight the sophisticated and persistent nature of Iranian cyber threat actors in pursuing malicious activities, emphasizing the importance of robust cybersecurity measures to defend against such attacks.

spot_img

Related articles

Recent articles

ThreatsDay Bulletin: Hybrid P2P Botnet Surges, 13-Year-Old Apache RCE Exploited, and Record $17.7 Billion Cyber Fraud Losses

ThreatsDay Bulletin: Hybrid P2P Botnet Surges, 13-Year-Old Apache RCE Exploited, and Record $17.7 Billion Cyber Fraud Losses In the ever-evolving landscape of cybersecurity, recent developments...

South African Court Strengthens Transparency by Ordering Eskom to Disclose $4.2 Billion Coal and Diesel Contracts

South African Court Strengthens Transparency by Ordering Eskom to Disclose $4.2 Billion Coal and Diesel Contracts In a landmark decision, South Africa’s Supreme Court of...

CID Launches Dual Probe into Police Involvement in Illegal Sand Mining and ₹6 Crore Extortion Claims

CID Launches Dual Probe into Police Involvement in Illegal Sand Mining and ₹6 Crore Extortion Claims Bhopal has become the focal point of significant scrutiny...

IFS Strategically Advances AI Solutions to Unlock Untapped Opportunities in the Middle East Market, Says Rahul Misra

IFS Strategically Advances AI Solutions to Unlock Untapped Opportunities in the Middle East Market, Says Rahul Misra In a rapidly evolving technological landscape, IFS is...