#RustyWater
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors thehackernews.com/2026/01/mudd...
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
MuddyWater launched RustyWater, a Rust-based RAT, via spear-phishing Word macros targeting Middle East organizations.
thehackernews.com
January 11, 2026 at 10:53 AM
-Dutch man sentenced for infecting port with malware
-Terrorism victims go after seized LuBian funds
-Most illegal crypto was linked to sanctions evasion
-Threat actors scan for LLM servers
-Report on the CrazyHunter ransomware, MuddyWater's RustyStealer and RustyWater
-SQLi in uni test platform
January 11, 2026 at 10:52 PM
Iran-linked MuddyWater APT deploys Rust-based implant in latest campaign www.csoonline.com/article/4115...
Iran-linked MuddyWater APT deploys Rust-based implant in latest campaign
Researchers discover RustyWater malware targeting organizations in Israel and other Middle Eastern countries
www.csoonline.com
January 13, 2026 at 2:42 AM
CloudSEK Report Reveals MuddyWater’s Shift to Advanced Rust-Based Cyber Espionage 

 A new threat intelligence report from CloudSEK has been published. Their research team has uncovered how the MuddyWater APT group—a known state-linked threat actor—has significantly evolved its attack tooling by…
CloudSEK Report Reveals MuddyWater’s Shift to Advanced Rust-Based Cyber Espionage 
 A new threat intelligence report from CloudSEK has been published. Their research team has uncovered how the MuddyWater APT group—a known state-linked threat actor—has significantly evolved its attack tooling by deploying a new Rust-based implant, which we've named "RustyWater." The report details an ongoing spear-phishing campaign targeting government, diplomatic, telecom, financial, and maritime organisations across the Middle East. What makes this campaign noteworthy is the group's move away from its traditional PowerShell and VBS-based tools to a more stealthy, modular, and resilient Rust implant that enables long-term persistence and low-noise espionage—making detection and response far more challenging for defenders.
itnerd.blog
January 9, 2026 at 1:43 PM
MuddyWater launches a spear-phishing campaign in the Middle East with RustyWater RAT, a Rust-based remote access trojan!

👉 sctocs.com/muddywater-r...
MuddyWater Launches RustyWater RAT Through Spear-Phishing Targeting Middle East Sectors - SCtoCS
MuddyWater is deploying the RustyWater RAT via spear-phishing campaigns targeting multiple sectors across the Middle East.
sctocs.com
January 11, 2026 at 12:35 AM
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
thehackernews.com
January 10, 2026 at 11:00 AM
MuddyWater APT Weaponizing Word Documents to Deliver ‘RustyWater’ Toolkit Evading AV and EDR Tools
MuddyWater APT Weaponizing Word Documents to Deliver 'RustyWater' Toolkit Evading AV and EDR Tools
cybersecuritynews.com
January 9, 2026 at 3:00 PM
Le groupe iranien MuddyWater lance RustyWater, un RAT Rust, via spear-phishing ciblant secteurs diplomatique, maritime, financier et télécom au Moyen-Orient 🌍📧. Implant sophistiqué pour contrôle et persistance. #CyberSecurity #IA #InnovationIA https://kntn.ly/8a03e5a0
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
MuddyWater launched RustyWater, a Rust-based RAT, via spear-phishing Word macros targeting Middle East organizations.
thehackernews.com
January 12, 2026 at 12:20 PM
"Iranian-linked group MuddyWater has deployed RustyWater, a Rust-based RAT, via spear-phishing attacks on Middle Eastern diplomatic, maritime, financial, and telecom sectors."
Iran-Linked MuddyWater Deploys Rust-Based RAT in Middle East Phishing Attacks
Iranian-linked group MuddyWater has deployed RustyWater, a Rust-based RAT, via spear-phishing attacks on Middle Eastern diplomatic, maritime, financial, and telecom sectors. This evolution enhances st...
www.webpronews.com
January 13, 2026 at 4:42 PM
January 12, 2026 at 8:00 PM
Iran-linked MuddyWater APT deploys Rust-based implant in latest campaign
Iran-linked advanced persistent threat group MuddyWater has deployed a Rust-based implant in an ongoing espionage campaign targeting organizations in Israel and other Middle Eastern countries, according to CloudSEK. CloudSEK’s TRIAD team said it identified the spear-phishing campaign targeting diplomatic, maritime, financial, and telecom entities across the Middle East. The campaign uses icon spoofing and malicious Word documents to deliver RustyWater, which the researchers described as “a Rust-based implant representing a significant upgrade to their traditional toolkit.” “Historically, Muddy Water has relied on PowerShell and VBS loaders for initial access and post-compromise operations,” the cybersecurity firm wrote in a blog post. “The introduction of Rust-based implants represents a notable tooling evolution toward more structured, modular, and low noise RAT capabilities.” MuddyWater, which Microsoft tracks as Mango Sandstorm and ProofPoint identifies as TA450, operates under Iran’s Ministry of Intelligence and Security, according to the US cybersecurity agency CISA. The group has been active since at least 2017, targeting government agencies, telecommunications providers, and critical infrastructure across the Middle East, Asia, and Europe, according to security firms. The research comes amid continued activity by MuddyWater throughout 2024 and into early 2025. ESET researchers published findings in December 2024 showing the group deployed the MuddyViper backdoor against Israeli organizations between September 2024 and March 2025. Security firms have also documented MuddyWater deploying BugSleep implants and using legitimate remote monitoring and management tools in recent campaigns. ## Spear-phishing delivery The attack chain begins with spear-phishing emails containing malicious ZIP archives, according to the blog post. The archives include a legitimate PDF document and a disguised executable file bearing a PDF icon. When victims execute the file, it displays the decoy PDF while executing the malware, the researchers wrote. They wrote that the initial loader establishes persistence through Windows Registry modifications and deploys RustyWater as a secondary payload. The implant communicates with command-and-control infrastructure using HTTP/HTTPS protocols and supports file system enumeration, command execution, and data exfiltration. CloudSEK identified command-and-control domains mimicking legitimate services, including infrastructure posing as Dropbox and WordPress platforms. Several domains were registered through Hostinger, a hosting provider the cybersecurity firm said has been frequently abused by threat actors. ## Rust offers evasion advantages CloudSEK researchers said RustyWater was developed in Rust, which they said is increasingly used by malware authors for its memory safety features and cross-platform capabilities, according to the blog post. Other state-sponsored groups, including Russia’s Gossamer Bear and China-linked actors, have also deployed Rust-based malware in recent campaigns, according to security researchers. The implant incorporates checks for virtual machine environments, debugging tools, and sandbox systems. “RustyWater begins execution by establishing anti-debugging and anti-tampering mechanisms,” the researchers wrote. “It registers a Vectored Exception Handler (VEH) to catch debugging attempts and systematically gathers victim machine information, including username, computer name, and domain membership.” RustyWater also uses string obfuscation and multi-stage payload delivery, the researchers said. The malware encrypts all strings using position-independent XOR encryption and implements randomized sleep intervals between command-and-control callbacks to avoid detection, according to the blog post. ## Broader targeting CloudSEK said its investigation primarily focused on targeting within Israel, but the researchers observed indicators suggesting MuddyWater may have expanded operations to include victims in India, the UAE, and other countries in the region. The campaign targeting Israeli entities used Hebrew-language decoy documents related to government agencies and the Israel Defense Forces, the blog post added. MuddyWater has focused on espionage operations aimed at collecting government and military intelligence, according to security researchers. Previous campaigns attributed to the group used various remote access tools and custom malware families, including the PhonyC2 command-and-control framework and legitimate remote administration tools like SimpleHelp. In November 2024, Amazon Threat Intelligence correlated MuddyWater activity with subsequent missile strikes, showing the group accessed compromised servers containing live CCTV feeds prior to attacks in Israel and the Red Sea. CloudSEK recommended organizations implement email security controls, conduct security awareness training to help employees identify phishing attempts, and deploy endpoint detection and response solutions capable of identifying suspicious process behavior and network communications patterns.
www.csoonline.com
January 12, 2026 at 7:22 PM
Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant
Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant
www.cloudsek.com
January 9, 2026 at 5:24 PM
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting diplomatic, maritime, financial, and telecom entities in the Middle East with a Rust-based impl…
#hackernews #news
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting diplomatic, maritime, financial, and telecom entities in the Middle East with a Rust-based implant codenamed RustyWater. "The campaign uses icon spoofing and malicious Word documents to deliver Rust based implants capable of asynchronous C2, anti-analysis, registry persistence, and modular
thehackernews.com
January 11, 2026 at 5:24 PM
MuddyWater Goes Rust: “RustyWater” Malware Wave Targets Middle East Diplomacy and Telecom Giants

Introduction A notorious state-linked hacking group has just rewritten its playbook. MuddyWater, a well-known advanced persistent threat (APT), is abandoning its traditional PowerShell toolkit and…
MuddyWater Goes Rust: “RustyWater” Malware Wave Targets Middle East Diplomacy and Telecom Giants
Introduction A notorious state-linked hacking group has just rewritten its playbook. MuddyWater, a well-known advanced persistent threat (APT), is abandoning its traditional PowerShell toolkit and embracing the Rust programming language to deploy a new generation of stealthy cyber weapons. Dubbed “RustyWater,” this malware campaign is already making waves across the Middle East, hitting diplomatic institutions, maritime operators, financial firms, and major telecom providers.
undercodenews.com
January 12, 2026 at 2:40 AM
SHOCKING CYBER ONSLAUGHT: Iran-Linked MuddyWater Targets Middle East Diplomacy and Finance in Ruthless Phishing Campaign

Introduction A sophisticated cyber-espionage group known as MuddyWater has launched a new wave of targeted attacks across the Middle East, focusing on high-value diplomatic and…
SHOCKING CYBER ONSLAUGHT: Iran-Linked MuddyWater Targets Middle East Diplomacy and Finance in Ruthless Phishing Campaign
Introduction A sophisticated cyber-espionage group known as MuddyWater has launched a new wave of targeted attacks across the Middle East, focusing on high-value diplomatic and commercial sectors. Using advanced spear-phishing techniques and a stealthy new malware strain called RustyWater, the group is once again proving its capability to infiltrate sensitive networks. This latest campaign highlights the growing risks faced by government bodies, maritime firms, financial institutions, and telecom providers in an increasingly hostile cyber landscape.
undercodenews.com
January 11, 2026 at 9:16 AM
Reborn In Rust: Muddy Water Evolves Tooling with RustyWater Implant https://packetstorm.news/news/view/40015 #news
January 9, 2026 at 10:42 PM
Static Kitten APT Unleashes RustyWater: A Rust-Based Implant Redefining Middle East Cyber Espionage + Video

Introduction: The threat landscape in the Middle East has witnessed a significant escalation with the emergence of Static Kitten, an Advanced Persistent Threat (APT) group targeting…
Static Kitten APT Unleashes RustyWater: A Rust-Based Implant Redefining Middle East Cyber Espionage + Video
Introduction: The threat landscape in the Middle East has witnessed a significant escalation with the emergence of Static Kitten, an Advanced Persistent Threat (APT) group targeting diplomatic, maritime, financial, and telecom sectors. Active as early as January 2026, this campaign marks a strategic evolution from traditional malware toolkits to sophisticated, modular implants like "RustyWater," a Rust-based Remote Access Trojan (RAT) designed for stealth and resilience.
undercodetesting.com
March 20, 2026 at 12:45 PM
MuddyWater threat actor has launched RustyWater Remote Access Trojan via spear-phishing, targeting Middle East sectors. Use caution with email attachments and verify sender authenticity.
January 10, 2026 at 11:00 AM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Saturday, January 10, 2026
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
MuddyWater launched RustyWater, a Rust-based RAT, via spear-phishing Word macros targeting Middle East organizations.
thehackernews.com
January 10, 2026 at 8:53 PM
Iranian cyber group MuddyWater deploys RustyWater RAT via spear-phishing, targeting Middle East sectors. Stay alert! #CyberSecurity #MuddyWater #RustyWater #SpearPhishing #MiddleEast Link: thedailytechfeed.com/muddywater-u...
January 11, 2026 at 4:01 PM
Iran-affiliated MuddyWater deploys a Rust-based implant called RustyWater (RUSTRIC) via spear-phishing Word macros to target diplomatic, maritime, financial, and telecom sectors.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
January 10, 2026 at 11:11 AM