Monday, 2 Feb 2026
  • About Us
  • Contact Us
  • Terms and Conditions
  • Privacy Policy
Subscribe
Life Care News
  • Home
  • Business
    • Business Wire
    • Globenews Wire
  • News
    NewsShow More
    World Customs Organization praises ‘e-commerce platform’ in trilingual report
    World Customs Organization praises ‘e-commerce platform’ in trilingual report
    31/12/2025
    Shri Acharya Devvrat, Governor of Gujarat, and Union Ministers Shri Kinjarapu Ram Mohan Naidu & Gajendra Singh Shekhawat Grace Namotsav at Sanskardham
    Shri Acharya Devvrat, Governor of Gujarat, and Union Ministers Shri Kinjarapu Ram Mohan Naidu & Gajendra Singh Shekhawat Grace Namotsav at Sanskardham
    31/12/2025
    International Forum “Problem-Solving City: Hong Kong as a Disputes Resolver”
    International Forum “Problem-Solving City: Hong Kong as a Disputes Resolver”
    28/12/2025
    Roca Group opens the Roca Delhi Gallery, its first in India, as part of its international network of design-led cultural spaces
    Roca Group opens the Roca Delhi Gallery, its first in India, as part of its international network of design-led cultural spaces
    28/12/2025
    Confidence Surges Among Small Enterprises Despite Global Headwinds, Reflecting India’s Strong Economic Momentum – ASSOCHAM Dun & Bradstreet Small Business Confidence Index
    Confidence Surges Among Small Enterprises Despite Global Headwinds, Reflecting India’s Strong Economic Momentum – ASSOCHAM Dun & Bradstreet Small Business Confidence Index
    27/12/2025
  • Tech
  • Health
  • Sports
  • Entertainment
  • Automobile
  • 🔥
  • news
  • global
  •  and
  •  the
  • announced
  • today
  • Business
  • Tech
  •  for
  • will
Font ResizerAa
Life Care NewsLife Care News
  • Home
  • Business
  • News
  • Tech
  • Health
  • Sports
  • Entertainment
  • Automobile
Search
  • Home
  • Business
    • Business Wire
    • Globenews Wire
  • News
  • Tech
  • Health
  • Sports
  • Entertainment
  • Automobile
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech

Irans MuddyWater targets critical infrastructure in Israel and Egypt, masquerades as Snake game ESET Research discovers

GlobeNews Wire
Last updated: 03/12/2025 2:32 AM
GlobeNews Wire
Share
7 Min Read
Irans MuddyWater targets critical infrastructure in Israel and Egypt, masquerades as Snake game  ESET Research discovers
SHARE
Irans MuddyWater targets critical infrastructure in Israel and Egypt, masquerades as Snake game  ESET Research discovers
  • ESET researchers have identified new MuddyWater (Iran-aligned cyberespionage group) activity primarily targeting critical infrastructure organizations in Israel, with one confirmed target in Egypt
  • The group used more advanced techniques to deploy MuddyViper, a new backdoor, by using a loader (Fooder) that reflectively loads it into memory and executes it.
  • ESET provides technical analyses of the tools used in this campaign.

MONTREAL and BRATISLAVA, Slovakia, Dec. 02, 2025 (GLOBE NEWSWIRE) — ESET researchers have identified new MuddyWater activity primarily targeting organizations in Israel, with one confirmed target in Egypt. The victims in Israel were in the technology, engineering, manufacturing, local government, and educational sectors. MuddyWater, also referred to as Mango Sandstorm or TA450, is an Iran-aligned cyberespionage group known for its persistent targeting of government and critical infrastructure sectors, often leveraging custom malware and publicly available tools, and has links to the Ministry of Intelligence and National Security of Iran. In this campaign, the attackers deployed a set of previously undocumented, custom tools with the objective of improving defense evasion and persistence. New backdoor MuddyViper enables the attackers to collect system information, execute files and shell commands, transfer files, and exfiltrate Windows login credentials and browser data. The campaign leverages additional credential stealers. Among these tools is Fooder, a custom loader that masquerades as the classic Snake game.

In this campaign, initial access is typically achieved through spearphishing emails, often containing PDF attachments that link to installers for remote monitoring and management (RMM) software hosted on free file-sharing platforms such as OneHub, Egnyte, or Mega. These links lead to the download of tools including Atera, Level, PDQ, and SimpleHelp. Among the tools deployed by MuddyWater operators is also the VAX One backdoor, named after the legitimate software which it impersonates: Veeam, AnyDesk, Xerox, and the OneDrive updater service.

The group’s continued reliance on this familiar playbook makes its activity relatively easy to detect and block. However, in this case, the group also used more advanced techniques to deploy MuddyViper, a new backdoor, by using a loader (Fooder) that reflectively loads MuddyViper into memory and executes it. Several versions of Fooder masquerade as the classic Snake game, hence the designation, MuddyViper. Another notable characteristic of Fooder is its frequent use of a custom delay function that implements the core logic of the Snake game, combined with “Sleep” API calls. These features are intended to delay execution in an attempt to hide malicious behavior from automated analysis systems. Additionally, MuddyWater developers adopted CNG, the next-generation Windows cryptographic API, which is unique for Iran-aligned groups and somewhat atypical across the broader threat landscape. During this campaign, the operators deliberately avoided hands-on-keyboard interactive sessions, which is a historically noisy technique often characterized by mistyped commands. Thus, while some components remain noisy and easily detected, as is typical for MuddyWater, overall this campaign shows signs of technical evolution – increased precision, strategic targeting, and a more advanced toolset.

The post-compromise toolset also includes multiple credential stealers: CE-Notes, which targets Chromium-based browsers; LP-Notes, which stages and verifies stolen credentials; and Blub, which steals login data from Chrome, Edge, Firefox, and Opera browsers.

MuddyWater was first introduced to the public in 2017 by Unit 42, whose description of the group’s activity is consistent with ESET’s profiling – a focus on cyberespionage, the use of malicious documents as attachments designed to prompt users to enable macros and bypass security controls, and primarily targeting entities located in the Middle East.

Notable past activities include Operation Quicksand (2020), a cyberespionage campaign targeting Israeli government entities and telecommunications organizations, which exemplifies the group’s evolution from basic phishing tactics to more advanced, multistage operations; and a campaign targeting political groups and organizations in Türkiye, demonstrating the group’s geopolitical focus, its ability to adapt social engineering tactics to local contexts, and reliance on modular malware and flexible C&C infrastructure.

ESET has documented multiple campaigns attributed to MuddyWater that highlight the group’s evolving toolset and shifting operational focus. In March and April 2023, MuddyWater targeted an unidentified victim in Saudi Arabia, and the group conducted a campaign in January and February 2025 that was notable for its operational overlap with Lyceum (an OilRig subgroup). This cooperation suggests that MuddyWater may be acting as an initial access broker for other Iran-aligned groups.

For a more detailed analysis of the latest MuddyWater campaign, check out the latest ESET Research blogpost “MuddyWater: Snakes by the riverbank” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Overview of Fooder loading MuddyViper or other supported payloads.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.

An infographic accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/6db9cd33-ad20-4e23-a745-e37898641b3d 

 
IBM Report: 13% Of Organizations Reported Breaches Of AI Models Or Applications, 97% Of Which Reported Lacking Proper AI Access Controls
Bybit TradFi Report: Private Data Suggests Market Steady Without U.S. Official Figures
Mandatory notice of shareholding 19 June 2025
Ancient Cities, New Rhythms: Cultural Heritage Inspiring the Future of Urban Development
LENZ Therapeutics Reports Third Quarter 2025 Financial Results and Recent Corporate Highlights
TAGGED: andactivityalsoamongattackersbackdoorcampaignclassiccommandscriticalcustomdeployeddiscoversegyptesetfilesfoodergamegovernmentgroupinfrastructureiranalignediransisraellinksloadermasqueradesmuddyvipermuddywaternewsoftenoneoperatorsResearchsectorssnakesoftwaretargetingtargetstoolswindows
Share This Article
Facebook Copy Link Print
- Advertisement -

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
PinterestPin
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow

Most Selling Products

Top Picks, Trending Now – Discover the Best Sellers!
Tecno Camon 20 Premier 5G

Tecno Camon 20 Premier 5G

Dark Welkin | 8GB RAM + 512GB Storage (Expandable RAM up to 16GB) | Industry’s 1st 50MP RGBW-Pro Camera | Segment-First 108MP Ultra-Wide Macro Lens | 6.67" 120Hz 10-bit AMOLED In-Display

iQOO Z10 Lite 5G

iQOO Z10 Lite 5G

Titanium Blue | 6GB RAM + 128GB Storage | Dimensity 6300 5G with 433K+ AnTuTu Score | Robust 6000mAh Battery | IP64 Rated + Military-Grade Shock Resistance

OnePlus 13s

OnePlus 13s

Black Velvet | 12GB RAM + 256GB Storage | Flagship Snapdragon® 8 Elite Chipset | Exceptional Battery Life in a Compact Form | Lifetime Display Warranty Included

Samsung Galaxy A55 5G

Samsung Galaxy A55 5G

Awesome Iceblue | 8GB RAM + 256GB Storage | Premium Metal Frame | 50MP OIS Main Camera with Nightography | IP67 Water & Dust Resistance | Gorilla Glass Victus+ | sAMOLED Display with Vision Booster

You Might Also Like

Using AI to Fight Overcrowded Animal Shelters – “CALL A PET” Launches on World Animal Day
Business

Using AI to Fight Overcrowded Animal Shelters – “CALL A PET” Launches on World Animal Day

05/10/2025
EverBridge Group and Cosmotec Forge Landmark Partnership
Health

EverBridge Group and Cosmotec Forge Landmark Partnership

21/09/2025
30 km/h Direct Impact Against 242 mm-high Obstacle: TIGGO7 CSH Passes Mexico Battery Scrape Test Without Critical Damage
Automobile

30 km/h Direct Impact Against 242 mm-high Obstacle: TIGGO7 CSH Passes Mexico Battery Scrape Test Without Critical Damage

31/07/2025
EUROPE’S 50 BEST BARS TO DEBUT, SPOTLIGHTING BARS ACROSS THE CONTINENT
Food

EUROPE’S 50 BEST BARS TO DEBUT, SPOTLIGHTING BARS ACROSS THE CONTINENT

04/12/2025
Life Care News
Facebook Twitter Youtube Rss Medium

Life Care News:


We increase the awareness of millions of users through our news networks. We are one of the most trusted news networks in the world.

Top Categories
  • Home
  • Business
  • News
  • Tech
  • Health
  • Sports
  • Entertainment
  • Automobile
Usefull Links
  • About Us
  • Contact Us
  • Terms and Conditions
  • Privacy Policy
Copyright © 2015 – 2025 LifeCareNews Network. All Rights Reserved. LIFE CARE IS REGISTERED MAGAZINE IN RNI, NO.GUJGUJ/2015/71283
Life Care NewsLife Care News
Copyright © 2015 - 2025 LifeCareNews Network. All Rights Reserved. LIFE CARE IS REGISTERED MAGAZINE IN RNI, NO.GUJGUJ/2015/71283
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?