Hacking

MuddyWater Rolls Out New “UDPGangster” Backdoor in Latest Attacks

Published  ·  2 min read

MuddyWater, the Iranian hacking group that seems to never take a day off has popped up again with a new backdoor called UDPGangster. Instead of the usual command-and-control traffic, it uses UDP to move quietly under the radar.

Fortinet’s researchers say the group has been focusing on targets in Turkey, Israel, and Azerbaijan. Nothing new there, the region has been on MuddyWater’s radar for years, but the way they’re doing it this time is a bit sneakier.

How They Get In
The whole thing starts with phishing emails. Classic move.
Some messages pretend to be from the Turkish Republic of Northern Cyprus Ministry of Foreign Affairs (a mouthful of a name) and invite the victim to an online seminar called “Presidential Elections and Results.”

Attached are two files, a ZIP and a Word document, both leading to the same place. If the victim opens the document and allows macros, the malware quietly kicks off.

To distract the user, the document displays a fake notice in Hebrew from Bezeq, the Israeli telecom provider, talking about upcoming service interruptions. It looks legitimate enough that most people won’t think twice.

Meanwhile, the macro decodes some hidden data, saves it as ui.txt, and launches it. That file is the actual UDPGangster malware.

Trying Hard Not to Get Caught
Once the malware runs, it immediately checks whether it’s being watched. And it’s picky.
It looks for virtual machines, debugging tools, small RAM sizes, suspicious MAC addresses, VMware processes.
If something looks wrong, it simply shuts down.
If everything looks normal, it moves on.

What It Does Next
UDPGangster starts collecting system info and sends it over UDP port 1269 to a command-and-control server. After that, the attacker can run commands, upload and download files, drop more malware, the usual remote-control stuff.
It also tweaks the Registry so it can stick around after a reboot.

Fortinet’s researcher Cara Lin summed it up well: this malware mixes old-school macro tricks with enough anti-analysis checks to make life miserable for anyone trying to study it.
This comes not long after ESET reported another MuddyWater tool, MuddyViper, being used against a wide range of Israeli organizations, from universities to transportation companies. Clearly, the group is staying active and experimenting with new tools.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067