• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Cyber firm links worldwide phishing campaign to Iran-backed hackers

Oct 22, 2025, 20:48 GMT+1Updated: 00:08 GMT+0

Singapore-based cybersecurity company Group-IB says hackers tied to Iran carried out a sophisticated global phishing campaign to steal sensitive data from international organizations.

In a detailed report released Wednesday, the firm accused MuddyWater of using compromised email accounts and legitimate internet tools to make its messages appear authentic.

“The incident underscores how state-backed threat actors continue to exploit trusted channels of communication to evade defenses and infiltrate high-value targets,” Group-IB said in a statement.

The attackers reportedly gained access to a corporate email account through NordVPN, a popular virtual private network service, and used it to send fake messages to multiple targets worldwide.

These emails contained malicious Microsoft Word attachments disguised as genuine correspondence.

When recipients opened the files, they were prompted to “enable content” — a step that secretly triggered harmful code. The code then installed malware known as the Phoenix backdoor, allowing the hackers to remotely control infected computers, collect data, and conduct further spying activities.

“By exploiting the trust and authority associated with legitimate correspondence, the campaign significantly increased its chances of deceiving recipients,” the firm added.

Group-IB said it linked the attack to MuddyWater with “high confidence,” based on the technical tools and methods used.

The Phoenix backdoor identified in this operation was version 4 of the malware, suggesting continued development by the group.

MuddyWater has been active since at least 2017 and is believed to operate under Iran’s Ministry of Intelligence and Security.

The group has previously targeted government agencies, energy firms, and telecommunications companies across the Middle East, Europe and North America.

Most Viewed

Iran rules out nuclear concessions even if US accepts Hormuz proposal
1

Iran rules out nuclear concessions even if US accepts Hormuz proposal

2
ANALYSIS

US and Iran want a deal, but neither wants to move first

3

Saudi Arabia, UAE urge Trump to maintain pressure on Iran - WSJ

4

Iran threatens regional air travel as US sanctions cut its flight links

5
ANALYSIS

Bareheaded mother, veiled daughter: Iran's schools keep a rule its streets have dropped

Banner
Banner

Spotlight

  • Iran’s oil industry has too many masters
    OPINION

    Iran’s oil industry has too many masters

  • Iran wrong to expect midterms to restrain Trump, former US official says

    Iran wrong to expect midterms to restrain Trump, former US official says

  • Trump may be buying time on Iran until after the midterms
    PODCAST

    Trump may be buying time on Iran until after the midterms

  • Pezeshkian’s Fox News nuclear overture draws hardline backlash
    INSIGHT

    Pezeshkian’s Fox News nuclear overture draws hardline backlash

  • US and Iran want a deal, but neither wants to move first
    ANALYSIS

    US and Iran want a deal, but neither wants to move first

  • Rushdie returns to the fatwa that nearly cost him his life

    Rushdie returns to the fatwa that nearly cost him his life

Banner
Banner