MuddyWater, an Iranian threat group linked to the Ministry of Intelligence and Security (MOIS), deployed a custom backdoor known as BugSleep or MuddyRot in phishing campaigns targeting organizations in Israel, Saudi Arabia, Turkey, Azerbaijan, India, and Portugal. Researchers said the actor had previously relied on legitimate remote management tools such as Atera Agent and ScreenConnect, but recent operations shifted to the bespoke implant, often delivered through compromised organizational email accounts and lure documents hosted on legitimate file-sharing services including Egnyte subdomains crafted to match sender identities and themes. Campaigns reportedly evolved from highly tailored municipal lures to broader webinar and online-course themes, with increased use of English-language content.
Technical analysis showed BugSleep is an actively developed remote access tool that supports command execution, reverse shell access, file upload and download, and persistence via scheduled tasks. The malware communicates over a custom command-and-control protocol on plain TCP, commonly using port 443, with payloads obfuscated through a simple byte-subtraction scheme and beacon data formatted as ComputerName/Username. Researchers also observed an in-memory loader with process injection, process-mitigation settings intended to interfere with EDR userland hooking in some variants, and frequent code changes suggesting weekly releases during 2024. Defensive guidance included newly published Snort detections 63937 and 63938, along with indicators covering C2 infrastructure, delivery URLs, sender IPs, and malware hashes.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Talos said researchers analyzed the MuddyRot/BugSleep implant in June 2024, reversing its bespoke TCP command-and-control protocol and documenting capabilities including reverse shell, file transfer, and persistence.
Since February 2024, Check Point identified more than 50 spear-phishing emails sent to hundreds of recipients across more than 10 sectors. The campaigns used compromised organizational email accounts and delivered either legitimate RMM tools such as Atera and ScreenConnect or the custom BugSleep backdoor.
Check Point reported that MuddyWater significantly increased phishing-driven activity targeting Israel after the Israel–Hamas war began in October 2023, while also operating against Saudi Arabia, Turkey, Azerbaijan, India, and Portugal.
Talos published a technical analysis of BugSleep, including a functional Python C2 server that emulated operator interactions and Snort detections for BugSleep traffic. The article released Snort SIDs 63937 and 63938 and documented related indicators of compromise.
Sekoia published research on a recent campaign in which MuddyWater replaced use of the Atera remote-management tool with its custom MuddyRot implant.
Check Point publicly reported that recent MuddyWater campaigns targeting organizations in Israel had deployed a previously undocumented custom backdoor dubbed BugSleep, describing it as an in-development implant with encrypted communications, scheduled-task persistence, and file-transfer and command-execution features.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 58 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourceresearch.checkpoint.com
Open sourceblog.sekoia.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.