Group-IB reported that the Iran-linked MuddyWater threat actor ran a phishing campaign against international organizations and government targets by abusing a compromised mailbox accessed through NordVPN. The emails carried malicious Microsoft Word documents that prompted victims to enable macros; embedded VBA then dropped the FakeUpdate injector, which decrypted and launched Phoenix backdoor v4. The malware provided persistence, command execution, and communication with the command-and-control domain screenai[.]online, enabling continued access after initial compromise.
Researchers attributed the activity to MuddyWater with high confidence based on malware overlaps, matching macro logic, shared infrastructure, and targeting patterns aligned with the group’s prior operations. The infrastructure also hosted a custom Chromium credential stealer and remote management tools including PDQ and Action1, indicating likely credential theft and follow-on access. Additional related samples pointed to concurrent or linked MuddyWater activity, including operations targeting the energy sector in the Middle East and North Africa, while prior reporting has described MuddyWater as an Iranian-linked umbrella of regionally focused subgroups.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Group-IB attributed the campaign to the Iran-linked APT MuddyWater with high confidence based on malware overlaps, matching macro logic, shared infrastructure, and targeting patterns. The report also identified a custom Chromium credential stealer, PDQ, and Action1 on attacker infrastructure, and noted overlapping activity including an energy-sector targeting cluster in the Middle East and North Africa.
According to Group-IB, when victims enabled macros, embedded VBA code dropped the FakeUpdate injector, which decrypted and launched Phoenix backdoor version 4. The malware provided persistence, command execution, and communication with the command-and-control domain screenai[.]online.
Group-IB reported that MuddyWater used a compromised mailbox accessed via NordVPN to send phishing emails with malicious Microsoft Word attachments to international organizations and government targets worldwide. The lures delivered macro-enabled documents that initiated the infection chain.
Cisco Talos published research describing MuddyWater as an Iranian-linked threat conglomerate made up of regionally focused subgroups. This established background attribution context for later MuddyWater-linked operations.
2 references tracked. Mallory keeps watching after this page renders.
group-ib.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.