Phoenix v4 is a customized Windows backdoor associated with MuddyWater, the Iranian state-linked espionage group also tracked as APT34, Helix Kitten, and OilRig. It has been used in phishing-led campaigns targeting government and international organizations in the Middle East and North Africa, including operations against more than 100 government-related entities. Reporting places its operational use in 2025 and identifies it as part of MuddyWater’s broader evolution toward combining bespoke malware with compromised email infrastructure, remote management tooling, and anonymization services.
Phoenix v4 is designed to provide persistent access, remote monitoring, and data exfiltration from compromised systems. Public reporting also links the broader Phoenix lineage from earlier variants through version 4, indicating continued development and refinement by its operators. In observed campaigns, Phoenix v4 was delivered through phishing emails sent from compromised mailboxes, with operators using NordVPN to obscure their activity. Separate reporting tied the same campaign cluster to a Chromium-focused credential-stealing payload disguised as a benign application, suggesting Phoenix v4 may be deployed alongside additional collection tooling.
The malware fits MuddyWater’s long-standing espionage tradecraft: credential-driven intrusion, stealthy persistence, collection from government and strategic targets, and follow-on remote access to support intelligence gathering. Targeting has centered on MENA government and international organizations, consistent with Iranian intelligence priorities. Phoenix v4 is best understood as a purpose-built backdoor used to maintain footholds, surveil victims, and support theft of sensitive information in state-aligned cyber espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These emails deliver Phoenix v4, a customized backdoor designed for persistence, data exfiltration, and remote monitoring.
These emails deliver Phoenix v4, a customized backdoor designed for persistence, data exfiltration, and remote monitoring.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-delivered malware family in the Phoenix lineage, observed in MENA-focused campaigns and carrying a Chromium_Stealer payload.
Named malware/campaign tool referenced in overlap with known MuddyWater operations involving OWA compromise.
A customized backdoor used in phishing-led espionage campaigns to maintain persistence, exfiltrate data, and remotely monitor victims.
Phoenix v4 is a backdoor used by the MuddyWater threat actor, delivered via FakeUpdate campaigns. It features COM-based persistence, live command-and-control (C2) infrastructure, and is part of a toolkit that includes credential stealing and remote management tool abuse.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.