PULSE NAME
The Latest MuddyWater Attack Framework
WHITE MuddyWater AlienVault 2024-04-08 Modified: 2024-05-08
30
IOCs
MEDIUM VOLUME
The post details the latest malicious activities of the Iranian threat actor group MuddyWater, also known as MERCURY. It sheds light on their evolving tactics and the introduction of a new command and control (C2) framework dubbed 'DarkBeatC2'. The report provides analysis of the group's recent campaigns, supply chain attacks, and their potential collaboration with other Iranian groups. It also explores their abuse of compromised accounts and infrastructure to conduct phishing attacks and deploy remote access tools (RATs) against Israeli organizations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Atera Agent Tactical RMM DarkBeatC2
Indicators of Compromise (30)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 32bfe46efceae5813b75b40852fde3c2 2024-04-08
FileHash-MD5 353b4643ec51ecff7206175d930b0713 2024-04-08
FileHash-MD5 3dd1f91f89dc70e90f7bc001ed50c9e7 2024-04-08
FileHash-MD5 b7d15723d7ef47497c6efb270065ed84 2024-04-08
FileHash-MD5 bede9522ff7d2bf7daff04392659b8a8 2024-04-08
FileHash-SHA1 a6e728c3331f46763f643f7192959716034767e5 2024-04-08
FileHash-SHA256 60c387d9d52c98de5c5d8453f64a6541ec4db645f6709d1fe51903182943438c 2024-04-08
URL http://googleonlinee.com/setting/8955224/r4WB7DzDOwfaHSevxHH0 2024-04-08
URL http://googleonlinee.com/zero/7878123/eUwYPH9eIbAOiLs 2024-04-08
URL http://googleonlinee.com/zero/8946172/0IGkmSybmd3BXIe 2024-04-08
URL http://googleonlinee.com/zero/8946172/eUwYPH9eIbAOiLs 2024-04-08
domain aramcoglobal.site 2024-04-08
domain asure-onlinee.com 2024-04-08
domain domainsoftcloud.com 2024-04-08
domain freeupload.store 2024-04-08
domain google-word.com 2024-04-08
domain googlelinks.net 2024-04-08
domain googleonlinee.com 2024-04-08
domain googlevalues.com 2024-04-08
domain mafateehgroup.com 2024-04-08
domain mafatehgroup.com 2024-04-08
domain microsoft-corp.com 2024-04-08
domain nc6010721b.biz 2024-04-08
domain security-onedrive.com 2024-04-08
domain softwaree-cloud.com 2024-04-08
domain vatacloud.com 2024-04-08
domain webapicloud.com 2024-04-08
domain webftpcloud.com 2024-04-08
domain websiteapicloud.com 2024-04-08
domain websiteftpcloud.com 2024-04-08