News Room
16
Share
Iranian State Actor MuddyWater Deploys New 'BugSleep' Backdoor in Targeted Middle East Espionage Operations
highState Cyber Warfare

Iranian State Actor MuddyWater Deploys New 'BugSleep' Backdoor in Targeted Middle East Espionage Operations

Cybersecurity researchers have identified a custom C++ backdoor dubbed 'BugSleep,' used by the Iranian MOIS-affiliated group MuddyWater to target critical sectors across Israel and the Middle East.

25 July 2026Last updated 20 August 20264 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
High
Actor Type:
Nation-State
Geography:
Middle East
Confidence:
High Confidence
Source:
Check Point Research
Read Time:
4 min

Executive Summary

Intelligence analysts at Encrygma have monitored a significant tactical shift by the Iranian state-sponsored threat actor known as MuddyWater (also tracked as Mango Sandstorm, Static Kitten, or MERCURY). In recent operations conducted within the last 48 hours, the group has transitioned from its traditional reliance on legitimate Remote Monitoring and Management (RMM) tools to the deployment of a bespoke, custom-developed backdoor identified as 'BugSleep.' This malware is specifically designed to facilitate long-term espionage, file exfiltration, and remote command execution within targeted governmental and municipal networks across the Middle East, with a high concentration of activity noted in Israel.

Threat Analysis

MuddyWater, which operates under the direction of Iran's Ministry of Intelligence and Security (MOIS), has historically utilized 'living-off-the-land' techniques by exploiting legitimate software like Atera, ScreenConnect, and RemoteUtilities. The shift to BugSleep represents an evolution in their maturity, likely intended to evade modern Endpoint Detection and Response (EDR) solutions that have become increasingly proficient at flagging unauthorized RMM usage. The current campaign utilizes spear-phishing as the primary entry vector, delivering weaponized PDF documents and ZIP archives containing the BugSleep loader. Targeted sectors include municipalities, travel agencies, media outlets, and government-adjacent organizations.

Technical Details

BugSleep is a sophisticated C++-based backdoor currently in an active state of development, as evidenced by frequent version updates and iterative bug fixes observed by researchers. The malware's execution chain begins with an obfuscated loader that employs multiple calls to the Windows Sleep API—a common sandbox evasion technique designed to outlast automated analysis environments.

Once resident in memory, BugSleep utilizes API hashing to dynamically resolve its required functions, further complicating static analysis. It establishes a persistent connection with a hardcoded Command and Control (C2) server via encrypted HTTP traffic. The backdoor's primary capabilities include:

  • Command Execution: Arbitrary execution of shell commands through cmd.exe.
  • File Management: Bidirectional file transfer (upload/download) between the host and the C2.
  • Process Injection: Ability to inject malicious shellcode into legitimate system processes like Chrome or Edge to maintain a stealthy footprint.

Attribution Assessment

Encrygma aligns with recent findings from Check Point Research and Unit 42, attributing this activity to MuddyWater with high confidence. The attribution is based on a combination of infrastructure overlaps with known MOIS-controlled IP addresses, the specific targeting profile consistent with Iranian geopolitical interests, and the use of phishing lures previously associated with the group's 'Mango Sandstorm' personas. The rapid development cycle of the BugSleep tool suggests a dedicated software engineering team supporting the MOIS operations.

Implications

The introduction of BugSleep indicates that Iranian state actors are investing more heavily in custom tooling to maintain access to high-value targets. As regional tensions remain elevated, this shift suggests a move toward more disciplined and resilient cyber-espionage frameworks that can survive in highly contested network environments. For defenders, this means that the absence of rogue RMM tools is no longer a definitive indicator of a clean environment; custom backdoor signatures must be integrated into threat-hunting workflows.

Recommendations

Encrygma recommends the following mitigations to counter this threat:

  1. Phishing Defense: Deploy advanced email security filters capable of scanning within password-protected ZIP files and analyzing embedded links in PDFs.
  2. Endpoint Hardening: Implement specific YARA rules to detect the API hashing patterns and Sleep-based evasion logic unique to BugSleep.
  3. Network Monitoring: Audit and restrict outbound traffic to unknown C2 infrastructures, particularly over ports commonly used for HTTP/S that exhibit beaconing patterns every 30 minutes.
  4. Credential Rotation: Enforce immediate credential resets for any accounts involved in recent phishing interactions to prevent follow-on lateral movement.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo