PULSE NAME
UDPGangster Campaigns Target Multiple Countries
WHITE PetrP.73 2025-12-06 Modified: 2026-01-05
17
IOCs
MEDIUM VOLUME
The UDPGangster campaigns reveal the use of advanced delivery methods and sophisticated evasion techniques associated with the MuddyWater threat actor group. Primarily, these campaigns utilize macro-based delivery mechanisms, which are often embedded in documents as a means to initiate attacks. The phishing emails employed in these campaigns impersonate credible sources such as the Turkish Republic of Northern Cyprus Ministry of Foreign Affairs. Recipients are lured to an online seminar on "Presidential Elections and Results," with the emails containing attachments named seminer.doc and http://seminer.zip. The sender’s address is crafted to closely resemble an official communication, and the content is presented in formal Turkish to lend authenticity.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (1 / 17 total)
All URL hostname FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 7bb0d162bbaa462c516502d1db56818d24ad825f SHA1 of 7ea4b307e84c8b32c0220eca13155a4cf66617241f96b8af26ce2db8115e3d53 2025-12-06