
An Iranian threat actor known as MuddyWater continues a long-standing tradition of relying on legitimate remote administration tools to loot targeted systems.
The nation-state group previously employed ScreenConnect, RemoteUtilities, and Syncro, but new analysis by Group-IB reveals the attackers used SimpleHelp remote support software in June 2022 .
MuddyWater has been active since at least 2017 and is rated as a subordinate element within Iran’s Ministry of Information and Security (MOIS). Primary targets include Turkey, Pakistan, UAE, Iraq, Israel, Saudi Arabia, Jordan, United States, Azerbaijan, and Afghanistan.
Group-IB Senior Threat Analyst Nikita Rostovtsev said:
“SimpleHelp has not been compromised and is being used as intended. The attackers found a way to download the tool from the official website and use it in their attacks.”

The exact distribution method used to drop the SimpleHelp sample is currently unknown, but the group has been known to send spear-phishing messages containing malicious links from mailboxes of companies that have already been compromised. increase.
Group-IB’s findings were corroborated by Slovak cybersecurity firm ESET earlier this year, revealing details of MuddyWater attacks in Egypt and Saudi Arabia. The attack required SimpleHelp to deploy the Ligolo reverse tunneling tool and a credential harvester called MKL64.
Master the Art of Dark Web Intelligence Gathering
Learn the art of extracting threat intelligence from the dark web – join us for this expert-led webinar!
Save my seat!
The Singapore-based company also said it had identified a previously unknown infrastructure operated by the group, as well as a PowerShell script capable of receiving commands from remote servers and sending results back to them. .
The disclosure comes just weeks after Microsoft detailed a group’s modus operandi to carry out devastating attacks in a hybrid environment under the guise of a ransomware operation.