Iranian state-aligned threat group MuddyWater has launched a new cyberespionage campaign targeting organizations in Israel and Egypt, with a focus on technology, engineering, manufacturing, local government, and educational sectors. Researchers from ESET and other security firms have identified that MuddyWater is using a novel loader, dubbed Fooder, which masquerades as the classic Snake video game to deliver a new backdoor called MuddyViper. This loader introduces execution delays, inspired by the Snake game's mechanics, to evade antivirus detection. The campaign also employs spearphishing emails with PDF attachments that link to remote monitoring and management software installers, hosted on free file-sharing services, to gain initial access.
The MuddyViper backdoor enables attackers to collect system information, execute files and shell commands, transfer files, and exfiltrate Windows login credentials and browser data. Additional tools, such as credential stealers and another backdoor named VAX One, have also been deployed. MuddyWater's evolving tactics, including the use of reflective loading for in-memory execution and the impersonation of legitimate software, demonstrate increased sophistication and a continued focus on defense evasion and persistence. Security researchers note the possibility that MuddyWater may be acting as an initial access broker for other Iranian threat actors, given observed overlaps in operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-02, ESET publicly reported that MuddyWater had evolved its tradecraft in the 2024-2025 campaign, highlighting the Snake-themed Fooder loader, the new MuddyViper backdoor, and expanded credential theft capabilities. ESET assessed the activity as showing increased sophistication and possible overlap or collaboration with other Iran-aligned actors such as Lyceum and OilRig.
ESET-tracked activity associated with this wave of MuddyWater intrusions ran through 2025-03-18. By that point, the campaign had affected 17 Israeli organizations and one Egyptian technology company according to later reporting.
After gaining access, the attackers deployed a previously undocumented in-memory backdoor dubbed MuddyViper, along with credential stealers including CE-Notes and LP-Notes, and in some reporting VAX One. The malware supported persistence, credential harvesting, command execution, and data exfiltration while using techniques such as reverse SOCKS5 tunneling and the Windows CNG cryptographic API for stealth.
During the campaign, MuddyWater used spear-phishing emails with PDF lures that led victims to remote monitoring and management tool installers hosted on free file-sharing services; one report also mentions exploitation of VPN vulnerabilities. The group delivered a custom loader called Fooder, disguised as the Snake video game and using delayed execution to evade automated defenses.
The Iran-aligned MuddyWater group launched a cyberespionage campaign primarily against organizations in Israel, with at least one victim in Egypt, spanning sectors such as government, telecom, energy, technology, manufacturing, transportation, utilities, and academia. Multiple reports place the start of the activity on 2024-09-30.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourcesecurityaffairs.com
Open sourcegovinfosecurity.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.