MuddyWater APT Uses RustyWater Malware in Spear-Phishing Campaign
First seen 9 Jan 2026, 19:00 UTC
•
•86% similarity
•35
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Iran-linked MuddyWater APT group has initiated a spear-phishing campaign targeting various sectors including diplomatic, maritime, financial, and telecom across the Middle East. They are utilizing weaponized Word documents to deploy a new Rust-based malware known as RustyWater, marking a shift from their previous PowerShell and VBS tools.
ThreatCluster AI
How this analysis works