Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

MuddyWater Deploys RustyWater RAT Through Sophisticated Spear-Phishing in Middle East

5587

MuddyWater Deploys RustyWater RAT Through Sophisticated Spear-Phishing in Middle East

New threat intelligence reveals that the Iranian-linked advanced persistent threat (APT) group MuddyWater has launched a targeted spear-phishing campaign using a Rust-based Remote Access Trojan (RAT) dubbed RustyWater against diplomatic, maritime, financial, and telecom entities in the Middle East.

Unlike previous campaigns that leveraged PowerShell and VBScript loaders or legitimate remote access tools, RustyWater represents a significant tooling evolution toward modular, low-noise malware capable of stealthy persistence and asynchronous command-and-control communication.

Attack delivery and mechanics

The campaign begins with spear-phishing emails, often masquerading as legitimate cybersecurity guidelines, containing a malicious Microsoft Word document. When victims open the attachment and enable macros, an embedded VBA macro reconstructs and deploys the RustyWater binary.

Once executed, RustyWater:

  • collects detailed system information;

  • detects installed security tools;

  • establishes persistence via Windows Registry keys;

  • communicates with its C2 infrastructure (e.g., nomercys.it[.]com) for further commands and file operations.

This advanced implant has also been referenced in limited reporting under aliases such as Archer RAT or RUSTRIC, though intelligence analysts use RustyWater for clarity and tracking.

Attribution and context

MuddyWater, tracked by multiple security organizations under names including TA450, Mango Sandstorm, and Static Kitten, is widely assessed as a state-affiliated threat actor and has been active since at least 2017, conducting persistent campaigns against various sectors.

DIAMATIX Perspective

This campaign highlights several advanced threat trends:

  • Migration to compiled, resilient implants
    Rust as a development language enables more secure, high-performance, and harder-to-detect malware compared to script- based or runtime-dependent tools.

  • Strategic use of social engineering
    Spear-phishing emails with embedded macros remain one of the most effective initial access vectors, especially when impersonating trusted entities.

  • Modular and persistent footholds
    Modern RATs like RustyWater are designed for long-term presence with minimal noise, demanding active detection strategies such as behavioral analysis and IOC correlation.

For enterprise defenders, this type of campaign underscores the need for:

  • robust macro execution controls,

  • enhanced sandboxing and detonation environments,

  • continuous endpoint monitoring and adaptive threat hunting,

  • strong email filtering and user awareness training.

Contact DIAMATIX

Trusted · Innovative · Vigilant


Sources

  • The Hacker News – RustyWater spear-phishing campaign report

  • CloudSEK threat research on Rust-based implants

  • IndustrialCyber contextual confirmation of delivery mechanics

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.