Unit 42 presents a comprehensive threat assessment of Boggy Serpens (MuddyWater), an Iranian nation-state cyberespionage group attributed to MOIS. Over the past year, the group has evolved from high-volume, low-sophistication phishing to a more targeted 'trusted relationship compromise' model, hijacking legitimate government
Table of contents
Executive SummaryBoggy Serpens OverviewCampaigns, Phishing Themes and Documents AnalysisMacros AnalysisBoggy Serpens Toolset OverviewConclusionIndicators of CompromiseAdditional ReferencesAppendix A: The Nuso Development TrackAppendix B: Deconstructing the Phoenix and UDPGangster VBA BuildersAppendix C: BlackBeard, a Backdoor Written in RustSort: