The Iranian state-linked threat actor MuddyWater has launched a cyber espionage campaign targeting organizations in Turkey, Israel, and Azerbaijan using a new backdoor named UDPGangster. This malware leverages the User Datagram Protocol (UDP) for command-and-control (C2) communications, enabling attackers to remotely control compromised systems, execute commands, exfiltrate files, and deploy additional payloads while evading traditional network defenses. The attack chain begins with spear-phishing emails impersonating government entities, such as the Turkish Republic of Northern Cyprus Ministry of Foreign Affairs, and includes malicious Microsoft Word documents that prompt users to enable macros, triggering the execution of the UDPGangster payload.
The VBA macro embedded in the malicious documents decodes Base64-encoded data and writes it to a file, which is then executed to launch the backdoor. UDPGangster establishes persistence through Windows Registry modifications and incorporates anti-analysis techniques to resist detection and analysis. The campaign demonstrates MuddyWater's continued evolution in using covert communication channels and sophisticated social engineering tactics to infiltrate targeted organizations in the Middle East region.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that MuddyWater deployed a new backdoor named UDPGangster that uses the UDP protocol for covert command-and-control communications. The malware establishes persistence, performs anti-analysis checks, and can exfiltrate data, execute commands, and deliver additional payloads.
The Iran-linked threat actor MuddyWater was observed conducting a targeted campaign against users in Turkey, Israel, and Azerbaijan using spear-phishing emails impersonating official entities. The emails delivered malicious Word documents that required macro activation to begin the infection chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.