PULSE NAME
UDPGangster Campaigns Target Multiple Countries
WHITE MuddyWater AlienVault 2025-12-10 Modified: 2026-01-09
15
IOCs
MEDIUM VOLUME
UDPGangster, a UDP-based backdoor associated with the MuddyWater threat group, has been observed targeting users in Turkey, Israel, and Azerbaijan. The malware is delivered through malicious Microsoft Word documents with embedded VBA macros, employing sophisticated anti-analysis techniques to evade detection. The campaigns use phishing emails impersonating government entities and include decoy images to distract victims. UDPGangster installs persistence, collects system information, and communicates with its command and control server using UDP. The malware supports various commands for remote execution, file extraction, and payload deployment. Analysis reveals connections to previous MuddyWater operations and shared infrastructure with other known malware.
Indicators of Compromise (1 / 15 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a9235540208fa6a25614c24a59e19199 2025-12-10