
Iranian State Actor MuddyWater Deploys New 'BugSleep' Backdoor in Targeted Middle East Espionage Operations
Cybersecurity researchers have identified a custom C++ backdoor dubbed 'BugSleep,' used by the Iranian MOIS-affiliated group MuddyWater to target critical sectors across Israel and the Middle East.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Middle East
- Confidence:
- High Confidence
- Source:
- Check Point Research
- Read Time:
- 4 min
Executive Summary
Intelligence analysts at Encrygma have monitored a significant tactical shift by the Iranian state-sponsored threat actor known as MuddyWater (also tracked as Mango Sandstorm, Static Kitten, or MERCURY). In recent operations conducted within the last 48 hours, the group has transitioned from its traditional reliance on legitimate Remote Monitoring and Management (RMM) tools to the deployment of a bespoke, custom-developed backdoor identified as 'BugSleep.' This malware is specifically designed to facilitate long-term espionage, file exfiltration, and remote command execution within targeted governmental and municipal networks across the Middle East, with a high concentration of activity noted in Israel.
Threat Analysis
MuddyWater, which operates under the direction of Iran's Ministry of Intelligence and Security (MOIS), has historically utilized 'living-off-the-land' techniques by exploiting legitimate software like Atera, ScreenConnect, and RemoteUtilities. The shift to BugSleep represents an evolution in their maturity, likely intended to evade modern Endpoint Detection and Response (EDR) solutions that have become increasingly proficient at flagging unauthorized RMM usage. The current campaign utilizes spear-phishing as the primary entry vector, delivering weaponized PDF documents and ZIP archives containing the BugSleep loader. Targeted sectors include municipalities, travel agencies, media outlets, and government-adjacent organizations.
Technical Details
BugSleep is a sophisticated C++-based backdoor currently in an active state of development, as evidenced by frequent version updates and iterative bug fixes observed by researchers. The malware's execution chain begins with an obfuscated loader that employs multiple calls to the Windows Sleep API—a common sandbox evasion technique designed to outlast automated analysis environments.
Once resident in memory, BugSleep utilizes API hashing to dynamically resolve its required functions, further complicating static analysis. It establishes a persistent connection with a hardcoded Command and Control (C2) server via encrypted HTTP traffic. The backdoor's primary capabilities include:
- Command Execution: Arbitrary execution of shell commands through cmd.exe.
- File Management: Bidirectional file transfer (upload/download) between the host and the C2.
- Process Injection: Ability to inject malicious shellcode into legitimate system processes like Chrome or Edge to maintain a stealthy footprint.
Attribution Assessment
Encrygma aligns with recent findings from Check Point Research and Unit 42, attributing this activity to MuddyWater with high confidence. The attribution is based on a combination of infrastructure overlaps with known MOIS-controlled IP addresses, the specific targeting profile consistent with Iranian geopolitical interests, and the use of phishing lures previously associated with the group's 'Mango Sandstorm' personas. The rapid development cycle of the BugSleep tool suggests a dedicated software engineering team supporting the MOIS operations.
Implications
The introduction of BugSleep indicates that Iranian state actors are investing more heavily in custom tooling to maintain access to high-value targets. As regional tensions remain elevated, this shift suggests a move toward more disciplined and resilient cyber-espionage frameworks that can survive in highly contested network environments. For defenders, this means that the absence of rogue RMM tools is no longer a definitive indicator of a clean environment; custom backdoor signatures must be integrated into threat-hunting workflows.
Recommendations
Encrygma recommends the following mitigations to counter this threat:
- Phishing Defense: Deploy advanced email security filters capable of scanning within password-protected ZIP files and analyzing embedded links in PDFs.
- Endpoint Hardening: Implement specific YARA rules to detect the API hashing patterns and Sleep-based evasion logic unique to BugSleep.
- Network Monitoring: Audit and restrict outbound traffic to unknown C2 infrastructures, particularly over ports commonly used for HTTP/S that exhibit beaconing patterns every 30 minutes.
- Credential Rotation: Enforce immediate credential resets for any accounts involved in recent phishing interactions to prevent follow-on lateral movement.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
