More

    Iranian MuddyWater hackers use compromised mailboxes for global phishing scams



    • Group-IB links a macro-based phishing campaign to Iranian threat actor MuddyWater
    • Attackers used fake emails and Word docs to deploy Phoenix v4 and other malware
    • Despite macro blocking since 2022, outdated techniques are still being used in the wild

    It’s October 2025, yet some cybercriminals are still trying to deliver malware via Microsoft Word macros, experts have warned.

    Recently, security researchers Group-IB discovered a new cyber-espionage campaign which begins with compromised email accounts, which the threat actors used to distribute phishing emails. These messages were targeting international organizations in different regions of the world, mimicking authentic correspondence to increase the chances of the victims actually opening up the emails.


    https://cdn.mos.cms.futurecdn.net/KpW9KtZSnVQtmgnPExTXED-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img