MuddyWater targeted organizations in Belarus, Turkey, and Ukraine with spear-phishing emails carrying Turkish-language Microsoft Word lure documents that used malicious macros to install malware. The initial document dropped a Delphi-based executable named CiscoAny.exe, established persistence through an .INF file and the Windows Run registry key, and collected host details before launching a second-stage Delphi payload. Researchers said the operation preserved strong overlaps with earlier MuddyWater tradecraft, including macro structure, function names, and delivery methods.
The second-stage malware checked internet connectivity, exfiltrated system information to 185.117.75[.]116.php, and pulled follow-on tasking from googleads.hopto[.]org, with POWERSTATS assessed as the likely next-stage payload. Check Point noted the campaign differed from prior MuddyWater activity because the second stage was not written in PowerShell, indicating the group was evolving its tooling while continuing parallel campaigns with at least two macro-generation approaches. The malware also used UPX packing and anti-analysis obfuscation to hinder detection and reverse engineering.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
A Palo Alto Networks LIVEcommunity post shared a Snort signature for detecting MoriAgent HTTP beaconing and multiple YARA rules for identifying MoriAgent and PowerStats malware artifacts associated with MuddyWater. The material described MoriAgent as a C++ MuddyWater implant and provided concrete detection logic for defenders.
The report states that MuddyWater has been active since at least 2017. This establishes the earliest known timeframe for the threat actor discussed in the campaign analysis.
Check Point Research analyzed a MuddyWater campaign targeting organizations in Belarus, Turkey, and Ukraine using Turkish-language malicious Word documents with macros. The campaign delivered Delphi-based malware, established persistence via an INF file and Run key, exfiltrated host data, and contacted command-and-control infrastructure for follow-on payloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.