Iranian MuddyWater hackers use compromised mailboxes for global phishing scams


  • Group-IB links a macro-based phishing campaign to Iranian threat actor MuddyWater
  • Attackers used fake emails and Word docs to deploy Phoenix v4 and other malware
  • Despite macro blocking since 2022, outdated techniques are still being used in the wild

It’s October 2025, yet some cybercriminals are still trying to deliver malware via Microsoft Word macros, experts have warned.

Recently, security researchers Group-IB discovered a new cyber-espionage campaign which begins with compromised email accounts, which the threat actors used to distribute phishing emails. These messages were targeting international organizations in different regions of the world, mimicking authentic correspondence to increase the chances of the victims actually opening up the emails.

#Iranian #MuddyWater #hackers #compromised #mailboxes #global #phishing #scams

Categories:

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts :-