216.73.217.22

Chronology of MuddyWater APT Attacks Targeting the Middle East

· Published 23/02/2026 09:34 · Modified 23/02/2026 09:50

Export JSON

Essential information

Published
23/02/2026 09:34
Modified
23/02/2026 09:50
Tags
2026-02-23 anydesk apt atera edr initial access intelligence gathering middle east remote management tools rust-based malware screenconnect spear-phishing splashtop syncro teamviewer
Related entities
20 observables, 1 intrusion sets (apt), 14 techniques (mitre), 6 malware, 15 others

Description

This report analyzes the recent activities of the MuddyWater group, which primarily targets organizations in the . The group employs sophisticated techniques, often impersonating legitimate entities and using malicious documents to gain . Their attacks focus on long-term infiltration and rather than immediate disruption. The report details several attack cases from 2019 to 2026, highlighting the group's evolving tactics, including the abuse of legitimate and the use of . The analysis emphasizes the importance of endpoint detection and response () solutions in identifying and mitigating these threats, as traditional perimeter-based security measures prove insufficient against such advanced persistent threats.

External references