Hacking

MuddyWater Deploys RustyWater RAT in Middle East Phishing Attacks

Published  ·  3 min read

The Iranian threat actor known as MuddyWater has been attributed to a new spear-phishing campaign targeting diplomatic, maritime, financial, and telecommunications organizations across the Middle East, delivering a previously undocumented Rust-based implant dubbed RustyWater.

According to a report published this week by CloudSEK, the campaign relies on icon spoofing and malicious Microsoft Word documents to deploy malware capable of asynchronous command-and-control (C2), anti-analysis, registry-based persistence, and modular post-exploitation functionality.

“The campaign uses icon spoofing and malicious Word documents to deliver Rust-based implants capable of asynchronous C2, anti-analysis, registry persistence, and modular post-compromise capability expansion,” said CloudSEK researcher Prajwal Awasthi.

A Shift in MuddyWater’s Tooling Strategy
Also tracked as Mango Sandstorm, Static Kitten, and TA450, MuddyWater is assessed to be affiliated with Iran’s Ministry of Intelligence and Security (MOIS) and has been active since at least 2017.

Previously, this group used primarily legit remote access tools and PowerShell-based loaders. Recently however, they appear to be shifting towards using more customized malware like Phoenix, UDPGangster, BugSleep (MuddyRot), MuddyViper and now also RustyWater.

This indicates a conscious move away from higher-noise malware designs with an intention to create lower-noise implant designs that will make it more difficult for modern endpoint protection solutions to analyze them.

Attack Chain Overview
The attack chain of RustyWater starts with spear phishing emails appearing to be sent from an authority on cybersecurity techniques that offer advice on how to combat cyber threats. Attached to these email messages is a harmful MS Word document.

By opening the attachment, you are presented with a notification that informs you of the need to enable content, which activates an embedded macro VBA that finally loads the RustyWater implant into your device.

RustyWater Capabilities
RustyWater, otherwise called Archer RAT (or RUSTRIC), provides a broad range of espionage-enabling functionality, which includes the following capabilities:
1. System and environment reconnaissance
2. Detection of installed security software
3. Windows Registry–based persistence
4. Asynchronous communication with a C2 server
5. Remote command execution and file manipulation via Remote Desktop Connection.

Using a command-and-control (C2) server located at nomercys.it[.]com, short for "no mercy," infection infrastructure is maintained over time by making outbound connections from the victim's computer to the designated C2 server. As such, the victim's compromised environment can be accessed by a threat actor for an extended period of time.

Broader Campaign Context
Use of the RUSTRIC malware family was also reported by Seqrite Labs late last month in attacks targeting IT firms, MSPs, HR departments, and software development companies in Israel. That activity is being tracked as UNG0801 / Operation IconCat, suggesting RustyWater is being deployed across multiple regional campaigns.


“The introduction of Rust-based implants represents a notable tooling evolution toward more structured, modular, and low-noise RAT capabilities,” CloudSEK noted.

Reasons for Importance
As Rust continues to be used for developing Malware and other types of threats which allows the creation of High Performing and Cross Platform Payloads therefore the artefact is likely to have High Resilience to Static Analysis Devices and Signature Based Devices used for detection. For Defenders, the Campaign serves to reinforce the importance of Macro Controls, Awareness of Phishing, and Behavioral Detection not just relying on traditional Indicators alone.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067