MuddyWater APT Uses RustyWater Malware in Spear-Phishing Campaign
Article Content
Browse articles
The Iran-linked MuddyWater APT group has initiated a spear-phishing campaign targeting various sectors including diplomatic, maritime, financial, and telecom across the Middle East. They are utilizing weaponized Word documents to deploy a new Rust-based malware known as RustyWater, marking a shift from their previous PowerShell and VBS tools.
Ask AI about this cluster
Answers cite the sources they use
Updated 196d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track MuddyWater and RustyWater in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered external Teams tenants with names resembling internal IT departments to gain trust. The campaign…
Iran's Ravin Academy Launches Largest Cyber Training Class Amid US-Iran Tensions Ravin Academy, an Iranian cybersecurity training firm, has announced its largest recruitment drive, seeking between 600 and 1,200 young Iranians for a free yearlong cybersecurity scholarship. This initiative occurs amid escalating cyberattacks attributed to Iran against US infrastructure. The US Treasury previously…