Click here to download all references as Bib-File.•
| 2025-07-21
            
            ⋅
            
            SentinelOne
            ⋅ SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers | 
| 2024-04-04
            
            ⋅
            
            Deep instinct
            ⋅ DarkBeatC2: The Latest MuddyWater Attack Framework MuddyC2Go | 
| 2023-11-08
            
            ⋅
            
            Deep instinct
            ⋅ MuddyC2Go – Latest C2 Framework Used by Iranian APT MuddyWater Spotted in Israel PhonyC2 MuddyC2Go | 
| 2023-11-01
            
            ⋅
            
            Deep instinct
            ⋅ MuddyWater eN-Able spear-phishing with new TTPs PhonyC2 | 
| 2023-09-14
            
            ⋅
            
            Deep instinct
            ⋅ Operation Rusty Flag – A Malicious Campaign Against Azerbaijanian Targets Unidentified 110 (RustyFlag) | 
| 2023-06-29
            
            ⋅
            
            DeepInstinct
            ⋅ PhonyC2: Revealing a New Malicious Command & Control Framework by MuddyWater PhonyC2 POWERSTATS | 
| 2023-03-09
            
            ⋅
            
            DeepInstinct
            ⋅ DUCKTAIL: Threat Operation Re-emerges with New LNK, PowerShell, and Other Custom Tactics to Avoid Detection DUCKTAIL | 
| 2022-12-08
            
            ⋅
            
            DeepInstinct
            ⋅ New MuddyWater Threat: Old Kitten; New Tricks | 
| 2022-06-01
            
            ⋅
            
            Deep instinct
            ⋅ Iranian Threat Actor Continues to Develop Mass Exploitation Tools CobaltMirage FRP | 
| 2022-03-21
            
            ⋅
            
            DeepInstinct
            ⋅ What is Arid Gopher? An Analysis of a New, Never-Before-Seen Malware Variant Arid Gopher AridHelper | 
| 2019-03-14
            
            ⋅
            
            Trustwave
            ⋅ Attacker Tracking Users Seeking Pakistani Passport scanbox | 
| 2017-12-19
            
            ⋅
            
            Trustwave
            ⋅ BrickerBot mod_plaintext Analysis BrickerBot |