Oasis Security researchers have uncovered a highly coordinated cyber campaign that scanned more than 12,000 internet-exposed systems ahead of targeted attacks on critical infrastructure in the Middle East.
The operation, active since early February, appears to be part of a structured reconnaissance-to-exfiltration workflow similar to tactics previously linked to the MuddyWater threat group.
The campaign followed a structured, multi‑stage sequence that began with broad, internet-wide scanning, transitioned to credential harvesting, and culminated in targeted exfiltration.
Oasis researchers found that the threat actor selectively exploited high‑value targets identified during the reconnaissance phase, demonstrating significant planning and resource allocation.
Five newly disclosed CVEs were central to the attackers’ initial scanning efforts:
- CVE‑2025‑54068 (Laravel Livewire RCE) – targeting modern web applications
- CVE‑2025‑52691 (SmarterMail RCE) – affecting mail server platforms
- CVE‑2025‑68613 (n8n RCE) – focused on workflow automation tools
- CVE‑2025‑9316 (RMM Session ID Generation Flaw) – targeting remote monitoring systems
- CVE‑2025‑34291 (Langflow RCE) – impacting AI workflow platforms
Advanced Command-and-Control Infrastructure
Analysis of the attacker-controlled infrastructure revealed a modular and multi-protocol C2 ecosystem.
Servers hosted in the Netherlands (IP: 157.20.182.49) coordinated various operational tasks, including scanning, credential harvesting, and data staging.

tcp_serv.py) using a custom <BIIH header structure (Source: oasis)Investigators noted consistent <BIIH> header structures across multiple controllers, suggesting that these components stemmed from a shared toolkit.
Several controllers shared operational patterns aligned with the ArenaC2 framework previously attributed to MuddyWater operations.

udp_3.0.py) using a custom <BIIH header structure (Source: oasis)This hybrid C2 model allowed flexible management of compromised systems and encrypted communications across multiple protocols, reinforcing the theory that the attackers relied on a battle‑tested, modular infrastructure used in prior Middle Eastern espionage campaigns.
Confirmed Data Exfiltration and Regional Focus
The final stage of the campaign involved structured data staging and exfiltration. Oasis researchers confirmed that approximately 200 files, including passport and payroll records, were extracted from an Egyptian aviation enterprise.
The directory structure of the attacker’s server revealed a clear organization by company name and data type, suggesting automated data collection pipelines.

The pattern of activity points to a regionally focused operation, with primary targeting observed in:
- Aviation and airline management organizations
- Energy and infrastructure companies
- National and local government entities
Additional reconnaissance traces were detected in Portugal and India, likely as part of broader discovery efforts rather than main objectives.
The campaign’s timeline coinciding with increased geopolitical tensions in the Middle East suggests a possible connection between the technical activity and broader regional intelligence objectives.
With characteristics reminiscent of MuddyWater tradecraft, including the reuse of C2 mechanisms and communication structures, this operation emphasizes the evolution of persistent, state-aligned reconnaissance behavior in the region.
Oasis Security concludes that the operation represents a highly coordinated, pipeline-driven attack chain, where reconnaissance, credential exploitation, and data exfiltration were executed as integrated phases rather than isolated events.
The scale and precision of the scanning effort spanning over 12,000 systems indicate continuous monitoring capabilities and deliberate high-value targeting rather than opportunistic exploitation.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.