Skip to content

MuddyWater APT Weaponizing Word Documents to Deliver ‘RustyWater’ Toolkit Evading AV and EDR Tools

Cybersecuritynews Tushar Subhra Dutta January 9, 2026

The Iran-linked MuddyWater Advanced Persistent Threat group has launched a sophisticated spear-phishing campaign targeting diplomatic, maritime, financial, and telecom sectors across the Middle East. The threat actors are using weaponized Word documents to deliver a new Rust-based malware called RustyWater, which represents a major change from their traditional PowerShell and VBS tooling. This upgraded implant […]

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Industries (1)

Malware (1)

MITRE ATT&CK (1)

Tools (1)