The Iran-linked MuddyWater advanced persistent threat (APT) group has shifted tactics by deploying a new malware family dubbed RustyWater, which is implemented in the Rust programming language. This marks a departure from their previous reliance on PowerShell-based payloads, with the new Rust-based implants designed to enhance stealth and evade detection. Security researchers have identified these implants being used in targeted attacks against organizations in Israel and other Middle Eastern countries.
The adoption of Rust for malware development by MuddyWater demonstrates an evolution in their tradecraft, likely aimed at bypassing traditional security controls that more readily detect PowerShell activity. The campaign highlights the ongoing threat posed by state-aligned actors in the region and underscores the need for organizations to update detection mechanisms to account for emerging malware written in less common languages such as Rust.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Security reporting on the campaign highlighted MuddyWater's move away from PowerShell toward a stealthier, more modular Rust-based implant. Researchers said the new malware supports asynchronous C2, anti-analysis checks, system reconnaissance, file operations, and command execution.
When victims enabled content in the booby-trapped Word documents, a VBA macro deployed a newly identified Rust-based implant called RustyWater. The malware established Windows Registry persistence and communicated with a command-and-control server at nomercys.it[.]com.
An Iran-linked MuddyWater operation targeted critical organizations across the Middle East, including diplomatic, maritime, financial, and telecommunications entities. The campaign used icon spoofing and malicious Microsoft Word documents that lured victims into enabling content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecsoonline.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.