APT group MuddyWater expanded its arsenal and uses new attack vectors

The Iranian APT group MuddyWater began using new attack vectors on telecommunications and governmental organizations.

According to the information security company Clearsky Security, MuddyWater has replenished its tactics, techniques and procedures (TTP) with new Microsoft Word documents that download malicious files through compromised servers, as well as documents that exploit CVE-2017-0199.

“The TTP includes decoy documents exploiting CVE-2017-0199 as the first stage of the attack. This is followed by the second stage of the attack – communication with the hacked C2 servers and downloading a file infected with the macros”, — inform in Clearsky Security.

Documents with VBA macros download malware masked as JPG on the attacked computer from a server located in the same country with the victim. This software exploits Microsoft Office/WordPad Remote Code Execution Vulnerability w/ Windows API (CVE-2017-0199) vulnerability and is detected by only three security solutions. For comparison, software used in past attacks was detected by 32 antivirus programs.

After the computer compromised, the malware tries to connect to the C&C server controlled by the attackers and, if it fails, the user redirected on Wikipedia.

Read also: Researchers told about new instruments of MuddyWater cybercriminal group

Band uses two types of malicious documents to exploit the vulnerability mentioned above. The first document uses error messages, and the second exploits the vulnerability immediately after its discovery by the victim.

The first document in turn loads malware of the first and second stage from the C&C server on the attacked system. Some documents use both attack vectors.


MuddyWater (aka SeedWorm/Temp.Zagros) is a high-profile Advanced Persistent Threat (APT) actor sponsored by Iran. The group was first observed in 2017, and since has operated multiple global espionage campaigns. With that in mind, their most significant operations mainly focus on Middle Eastern and Middle Asian nations.

The group targets a wide gamut of sectors, including governmental, military, telecommunication, and academia.

Source: https://www.clearskysec.com

About Trojan Killer

Carry Trojan Killer Portable on your memory stick. Be sure that you’re able to help your PC resist any cyber threats wherever you go.

Check Also

MageCart on the Heroku Cloud Platform

Researchers Found Several MageCart Web Skimmers On Heroku Cloud Platform

Researchers at Malwarebytes reported about finding several MageCart web skimmers on the Heroku cloud platform …

Android Spyware CallerSpy

CallerSpy spyware masks as an Android chat application

Trend Micro experts discovered the malware CallerSpy, which masks as an Android chat application and, …

Leave a Reply