TI Mindmap HUB
Threat Intelligence Report

Analysis of MuddyWater’s recent phishing attack activities

📅 November 17, 2025 📰 mp.weixin.qq.com 🔍 0 CVE(s) referenced

In recent operations, the MuddyWater group has conducted phishing attacks by disguising malicious content as PDFs and macro-enabled documents, delivering customized backdoors such as UDPGangster and Phoenix. These activities demonstrate covert, tailored infiltration techniques targeting the Middle East as well as Europe and the United States, with continuous iterations of attack payloads to evade detection.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle