UDPGangster Campaigns Target Multiple Countries
Dec. 21, 2025, 6:55 p.m.
Description
UDPGangster, a UDP-based backdoor associated with the MuddyWater threat group, has been observed targeting users in Turkey, Israel, and Azerbaijan. The malware is delivered through malicious Microsoft Word documents with embedded VBA macros, employing sophisticated anti-analysis techniques to evade detection. The campaigns use phishing emails impersonating government entities and include decoy images to distract victims. UDPGangster installs persistence, collects system information, and communicates with its command and control server using UDP. The malware supports various commands for remote execution, file extraction, and payload deployment. Analysis reveals connections to previous MuddyWater operations and shared infrastructure with other known malware.
Tags
Date
- Created: Dec. 10, 2025, 9:44 a.m.
- Published: Dec. 10, 2025, 9:44 a.m.
- Modified: Dec. 21, 2025, 6:55 p.m.
Indicators
- d177cf65a17bffcd152c5397600950fc0f81f00990ab8a43d352f9a7238428a1
- 01b1073cb0480af3bde735f559898774e1a563e06f9fe56ec3845ea960da0f3c
- 3d3fbd586f61043ff04ab0369b913a161c0159425fb269d52b7d8d8a14838ece
- 232e979493da5329012022d3121300a4b00f813d5b0ecc98fdc3278d8f4e5a48
- b7276cad88103bdb3666025cf9e206b9fb3e66a6d934b66923150d7f23573b60
- bca7d23b072a2799d124977fdb8384325b30bb1d731741d84a1dfc5e3cf6ac26
- e84a5878ea14aa7e2c39d04ea7259d7a4ed7f666c67453a93b28358ccce57bc5
- b552e1ca3482ad4b37b1a50717ac577e1961d0be368b49fa1e4e462761ae6eeb
- 7ea4b307e84c8b32c0220eca13155a4cf66617241f96b8af26ce2db8115e3d53
- 44deab99e22340fc654494cc4af2b2c27ef1942c6fea6eace9fb94ce7855c0ca
- fc4a7eed5cb18c52265622ac39a5cef31eec101c898b4016874458d2722ec430
- 13d36f3011ed372ad4ec4ace41a6dee52361f221161192cb49c08974c86d160e
- 157.20.182.75
- 64.7.198.12
- https://reminders.trahum.org/Scheduled_Internet_Outages.doc
Additional Informations
- Government and administrations
- Israel
- Azerbaijan