PULSE NAME
The Latest MuddyWater Attack Framework
WHITE MuddyWater AlienVault 2024-04-08 Modified: 2024-05-08
30
IOCs
MEDIUM VOLUME
The post details the latest malicious activities of the Iranian threat actor group MuddyWater, also known as MERCURY. It sheds light on their evolving tactics and the introduction of a new command and control (C2) framework dubbed 'DarkBeatC2'. The report provides analysis of the group's recent campaigns, supply chain attacks, and their potential collaboration with other Iranian groups. It also explores their abuse of compromised accounts and infrastructure to conduct phishing attacks and deploy remote access tools (RATs) against Israeli organizations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Atera Agent Tactical RMM DarkBeatC2
Indicators of Compromise (5 / 30 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 32bfe46efceae5813b75b40852fde3c2 2024-04-08
FileHash-MD5 353b4643ec51ecff7206175d930b0713 2024-04-08
FileHash-MD5 3dd1f91f89dc70e90f7bc001ed50c9e7 2024-04-08
FileHash-MD5 b7d15723d7ef47497c6efb270065ed84 2024-04-08
FileHash-MD5 bede9522ff7d2bf7daff04392659b8a8 2024-04-08