#BugSleep
Writing a BugSleep C2 server and detecting its traffic with Snort
Writing a BugSleep C2 server and detecting its traffic with Snort
This blog will demonstrate the practice and methodology of reversing BugSleep’s protocol, writing a functional C2 server, and detecting this traffic with Snort.
buff.ly
November 8, 2024 at 9:12 AM
MuddyWater hackers deploy new BugSleep backdoor malware in attacks
New BugSleep malware implant deployed in MuddyWater attacks
The Iranian-backed MuddyWatter hacking group has partially switched to using a new custom-tailored malware implant to steal files and run commands on compromised systems.
www.bleepingcomputer.com
July 15, 2024 at 6:46 PM
Iranian Cyber Threat Group Drops New Backdoor, 'BugSleep'
Iranian Threat Group Drops New Backdoor, 'BugSleep'
The group — which has targeted Israel, Saudi Arabia, and other nations — often uses spear phishing and legitimate remote management tools but is developing a brand-new homegrown toolset.
www.darkreading.com
July 18, 2024 at 6:17 AM
Iran's MuddyWater phishes Israeli orgs with custom BugSleep backdoor
Iran's MuddyWater phishes Israel with custom backdoor
India, Turkey, also being targeted by campaign that relies on corporate email compromise
www.theregister.com
July 17, 2024 at 12:25 AM
India, Turkey, also being targeted by campaign that relies on corporate email compromise MuddyWater, an Iranian government-backed cyber espionage crew, has upgraded its malware with a custom backdoor, which it's used to target Israeli organizations.…
Iran's MuddyWater phishes Israeli orgs with custom BugSleep backdoor
India, Turkey, also being targeted by campaign that relies on corporate email compromise MuddyWater, an Iranian government-backed cyber espionage crew, has upgraded its malware with a custom backdoor, which it's used to target Israeli organizations.…
go.theregister.com
July 17, 2024 at 12:30 AM
MuddyWater、中東の各分野を標的にスピアフィッシングでRustyWater RATを展開

イランの脅威アクターとして知られるMuddyWaterが、Rustベースのインプラント「RustyWater」を用い、中東の外交、海運、金融、通信関連の組織を標的としたスピアフィッシング・キャンペーンに関与しているとされている。 「このキャンペーンは、アイコンの偽装と悪意のあるWord文書を用いて、非同期C2、解析回避、レジストリによる永続化、侵害後の機能拡張をモジュール式に行えるRustベースのインプラントを配布します」と、CloudSEKのリセッターであるPrajwal…
MuddyWater、中東の各分野を標的にスピアフィッシングでRustyWater RATを展開
イランの脅威アクターとして知られるMuddyWaterが、Rustベースのインプラント「RustyWater」を用い、中東の外交、海運、金融、通信関連の組織を標的としたスピアフィッシング・キャンペーンに関与しているとされている。 「このキャンペーンは、アイコンの偽装と悪意のあるWord文書を用いて、非同期C2、解析回避、レジストリによる永続化、侵害後の機能拡張をモジュール式に行えるRustベースのインプラントを配布します」と、CloudSEKのリセッターであるPrajwal Awasthiは、今週公開されたレポートで述べた。 今回の最新動向は、MuddyWaterの手口が継続的に進化していることを示している。同グループは、侵害後のツールとして正規のリモートアクセスソフトウェアへの依存を徐々に、しかし着実に減らし、Phoenix、UDPGangster、BugSleep(別名MuddyRot)、MuddyViperといったツールを含む多様なマルウェア・アーセナルへと移行している。 このハッキンググループは、Mango Sandstorm、Static Kitten、TA450としても追跡されており、イラン情報省(MOIS)に関連していると評価されている。少なくとも2017年から活動している。 RustyWaterを配布する攻撃チェーンは比較的単純だ。サイバーセキュリティのガイドラインを装ったスピアフィッシングメールにMicrosoft Word文書が添付されており、これを開くと、悪意のあるVBAマクロの実行を有効化するために「コンテンツの有効化」を行うよう被害者に指示する。このマクロがRust製インプラントのバイナリを展開する役割を担う。 Archer RATおよびRUSTRICとも呼ばれるRustyWaterは、被害者マシンの情報を収集し、インストールされているセキュリティソフトを検出し、Windowsレジストリキーによって永続化を設定し、ファイル操作とコマンド実行を可能にするため、コマンド&コントロール(C2)サーバー(「nomercys.it[.]com」)との通信を確立する。 なお、RUSTRICの使用は、イスラエルの情報技術(IT)、マネージドサービスプロバイダー(MSP)、人事、ソフトウェア開発企業を標的とした攻撃の一環として、先月末にSeqrite Labsが指摘している。この活動は、同サイバーセキュリティ企業によりUNG0801およびOperation IconCatの名称で追跡されている。 「歴史的に、MuddyWaterは初期侵入および侵害後の活動にPowerShellとVBSローダーを利用してきました」とCloudSEKは述べた。「Rustベースのインプラントの導入は、より構造化され、モジュール化され、ノイズの少ないRAT機能へとツールが顕著に進化していることを示しています」 翻訳元:
blackhatnews.tokyo
January 10, 2026 at 11:07 AM
Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks #cybersecurity #infosec #privacy #news thehackernews.com/20...
July 16, 2024 at 2:40 PM
Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks

#thehackersnews
Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks
Iranian hacker group MuddyWater shifts tactics, deploying new backdoor BugSleep in cyberattacks targeting Middle East and European countries.
thehackernews.com
July 16, 2024 at 10:35 AM
Nuevo malware BugSleep implementado en ataques MuddyWater. (Inglés)

Vía: BleepingComputer
New BugSleep malware implant deployed in MuddyWater attacks
The Iranian-backed MuddyWatter hacking group has partially switched to using a new custom-tailored malware implant to steal files and run commands on compromised systems.
www.bleepingcomputer.com
July 15, 2024 at 8:14 PM