Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access
Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access
18 April 2023
The Iranian threat actor known as MuddyWater is continuing its time-tested tradition of relying on legitimate remote administration tools to commandeer targeted systems.
While the nation-state group has previously employed ScreenConnect, RemoteUtilities, and Syncro, a new analysis from Group-IB has revealed the adversary's use of the SimpleHelp remote support software in June 2022.
MuddyWater,