MuddyWater Deploys RustyWater RAT Through Sophisticated Spear-Phishing in Middle East
New threat intelligence reveals that the Iranian-linked advanced persistent threat (APT) group MuddyWater has launched a targeted spear-phishing campaign using a Rust-based Remote Access Trojan (RAT) dubbed RustyWater against diplomatic, maritime, financial, and telecom entities in the Middle East.
Unlike previous campaigns that leveraged PowerShell and VBScript loaders or legitimate remote access tools, RustyWater represents a significant tooling evolution toward modular, low-noise malware capable of stealthy persistence and asynchronous command-and-control communication.
Attack delivery and mechanics
The campaign begins with spear-phishing emails, often masquerading as legitimate cybersecurity guidelines, containing a malicious Microsoft Word document. When victims open the attachment and enable macros, an embedded VBA macro reconstructs and deploys the RustyWater binary.
Once executed, RustyWater:
collects detailed system information;
detects installed security tools;
establishes persistence via Windows Registry keys;
communicates with its C2 infrastructure (e.g.,
nomercys.it[.]com) for further commands and file operations.
This advanced implant has also been referenced in limited reporting under aliases such as Archer RAT or RUSTRIC, though intelligence analysts use RustyWater for clarity and tracking.
Attribution and context
MuddyWater, tracked by multiple security organizations under names including TA450, Mango Sandstorm, and Static Kitten, is widely assessed as a state-affiliated threat actor and has been active since at least 2017, conducting persistent campaigns against various sectors.
DIAMATIX Perspective
This campaign highlights several advanced threat trends:
Migration to compiled, resilient implants
Rust as a development language enables more secure, high-performance, and harder-to-detect malware compared to script- based or runtime-dependent tools.Strategic use of social engineering
Spear-phishing emails with embedded macros remain one of the most effective initial access vectors, especially when impersonating trusted entities.Modular and persistent footholds
Modern RATs like RustyWater are designed for long-term presence with minimal noise, demanding active detection strategies such as behavioral analysis and IOC correlation.
For enterprise defenders, this type of campaign underscores the need for:
robust macro execution controls,
enhanced sandboxing and detonation environments,
continuous endpoint monitoring and adaptive threat hunting,
strong email filtering and user awareness training.
Trusted · Innovative · Vigilant
Sources
The Hacker News – RustyWater spear-phishing campaign report
CloudSEK threat research on Rust-based implants
IndustrialCyber contextual confirmation of delivery mechanics






