{"id":3534,"date":"2021-08-13T22:16:56","date_gmt":"2021-08-14T03:16:56","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3534"},"modified":"2021-08-13T22:16:57","modified_gmt":"2021-08-14T03:16:57","slug":"muddywater-a-cybercriminal-group-since-2017","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/","title":{"rendered":"MuddyWater &#8211; A cybercriminal group since 2017"},"content":{"rendered":"\n<p>This cyber espionage group (MuddyWater) is believed to be outside of Iran and is known for targeting telecommunications providers and government agencies in the Middle East. This group has increased its malware arsenal since its creation in 2017 or at least it is believed that it has been active since that date. This group is known for creating software to attack Android devices as well as creating new backdoor malware to spy on their targets, and they have also been discovered using false flag tactics to mislead investigators.<\/p>\n\n\n\n<p>In addition, in their recent malicious activities, MuddyWater carried out events in the Middle East and the surrounding areas in which they used the remote management tools ScreenConnect and RemoteUtilities. The researchers who discovered this threat called Trend Micro called these intrusion tools Earth Vetala.<\/p>\n\n\n\n<p>Earth Vetala uses emails launched with embedded links that point to legitimate file sharing services and are used to distribute malicious software packages. The links are embedded in decoy documents and emails, and the researchers noted that the strategies and techniques used in the two campaigns to distribute RemoteUtilities and ScreenConnect were roughly similar. They stated that the targets of the new campaign were primarily organizations located in Azerbaijan, Bahrain, Israel, Saudi Arabia and the United Arab Emirates.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/blackmatter-new-threat-group-emerges\/\">BlackMatter new threat group emerges<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/magecart-group-targeting-online-shopping\/\">Magecart group targeting online shopping<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This cyber espionage group (MuddyWater) is believed to be outside of Iran and is known for targeting telecommunications providers and government agencies in the Middle East. This group has increased its malware arsenal since its creation in 2017 or at least it is believed that it has been active since that date. This group is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3535,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3534","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>MuddyWater - A cybercriminal group since 2017 - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we will see a cybercriminal group which is believed to have been active since the years 2017 called MuddyWater........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MuddyWater - A cybercriminal group since 2017 - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we will see a cybercriminal group which is believed to have been active since the years 2017 called MuddyWater........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-14T03:16:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-14T03:16:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Muddy.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuto\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"MuddyWater &#8211; A cybercriminal group since 2017\",\"datePublished\":\"2021-08-14T03:16:56+00:00\",\"dateModified\":\"2021-08-14T03:16:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/\"},\"wordCount\":228,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Muddy.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/\",\"name\":\"MuddyWater - A cybercriminal group since 2017 - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Muddy.jpg\",\"datePublished\":\"2021-08-14T03:16:56+00:00\",\"dateModified\":\"2021-08-14T03:16:57+00:00\",\"description\":\"Today we will see a cybercriminal group which is believed to have been active since the years 2017 called MuddyWater........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Muddy.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Muddy.jpg\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/muddywater-a-cybercriminal-group-since-2017\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"MuddyWater &#8211; A cybercriminal group since 2017\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"MuddyWater - A cybercriminal group since 2017 - Truxgo Server Blog","description":"Today we will see a cybercriminal group which is believed to have been active since the years 2017 called MuddyWater........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/","og_locale":"es_MX","og_type":"article","og_title":"MuddyWater - A cybercriminal group since 2017 - Truxgo Server Blog","og_description":"Today we will see a cybercriminal group which is believed to have been active since the years 2017 called MuddyWater........","og_url":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-08-14T03:16:56+00:00","article_modified_time":"2021-08-14T03:16:57+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Muddy.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"1 minuto"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"MuddyWater &#8211; A cybercriminal group since 2017","datePublished":"2021-08-14T03:16:56+00:00","dateModified":"2021-08-14T03:16:57+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/"},"wordCount":228,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Muddy.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/","url":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/","name":"MuddyWater - A cybercriminal group since 2017 - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Muddy.jpg","datePublished":"2021-08-14T03:16:56+00:00","dateModified":"2021-08-14T03:16:57+00:00","description":"Today we will see a cybercriminal group which is believed to have been active since the years 2017 called MuddyWater........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Muddy.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Muddy.jpg","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/muddywater-a-cybercriminal-group-since-2017\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"MuddyWater &#8211; A cybercriminal group since 2017"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3534","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3534"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3534\/revisions"}],"predecessor-version":[{"id":3883,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3534\/revisions\/3883"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3535"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3534"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3534"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3534"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}