New MuddyWater attacks involve SimpleHelp remote admin tool

Iranian state-sponsored threat operation MuddyWater has been using SimpleHelp remote support software to ensure persistence in devices that have been compromised in attacks since June 2022, according to The Hacker News. While no exact approach for SimpleHelp distribution has been detailed, spear-phishing messages have been commonly leveraged by MuddyWater to facilitate its intrusions, a report from Group-IB showed.

Read full article on SC Magazine

 


Date:

Categorie(s):

Tag(s):