Iranian Espionage Operations Linked To CastleRAT and ChainShell Malware Suite

Recent threat intelligence has uncovered a direct operational link between Iran’s MuddyWater espionage group and the Russian-developed TAG-150 CastleRAT platform.

According to a JUMPSEC report, this marks a significant shift, with state-sponsored attackers actively using commercial cybercrime malware-as-a-service (MaaS) ecosystems.

Investigators found that MuddyWater, a group tied to Iran’s Ministry of Intelligence and Security (MOIS), is using at least two CastleRAT builds alongside a newly discovered malware named ChainShell.

State Hackers Adopt Criminal Tools

MuddyWater has historically relied on custom backdoors and legitimate remote management tools to target the defense, aerospace, and energy sectors, primarily focusing on Israel and the West.

However, adopting the Russian CastleRAT platform grants the Iranian group immediate access to advanced capabilities without in-house development.

These tools include Chrome cookie decryption, keylogging, and Hidden VNC, which allow attackers to control an infected system’s desktop secretly. At the same time, the legitimate user is still active.

Iran Tied to CastleRAT (Source: jumpsec)
Iran Tied to CastleRAT (Source: jumpsec)

This convergence of state espionage and criminal MaaS creates a major challenge for network defenders.

Because the malware contains Russian-language strings and intentionally avoids infecting systems in post-Soviet countries, security teams might initially misattribute an intrusion to ordinary Russian cybercriminals.

This misclassification can delay the appropriate incident response required for a state-level espionage campaign.

Researchers confirmed that MuddyWater is merely a customer of this shared platform, using the same underlying technology as other threat actors, such as the LeakNet ransomware group.

Iran Tied to CastleRAT (Source: jumpsec)
Iran Tied to CastleRAT (Source: jumpsec)

The ChainShell Payload and Evidence

The connection between MuddyWater and the TAG-150 platform was cemented by the discovery of an exposed command-and-control (C2) server.

This misconfigured server contained Farsi code comments, Israeli target IP lists, and a malicious PowerShell script named reset.ps1.

Iran Tied to CastleRAT (Source: jumpsec)
Iran Tied to CastleRAT (Source: jumpsec)

This script deploys “ChainShell,” a previously undocumented Node.js agent.

ChainShell operates as a thin execution shell that securely communicates with its C2 by dynamically resolving addresses through the Ethereum blockchain, making the attacker’s infrastructure highly resilient against network takedowns.

Further technical JUMPSEC evidence ties the entire campaign together through shared code-signing certificates.

A certificate issued to the name “Amy Cherne” was used to sign both known MuddyWater tools (such as StageComp) and the installer for CastleRAT payloads.

This certificate chain, combined with identical campaign identifiers like the name “Smokest,” proves that the same operator deployed both sets of tools.

Additionally, attackers hid native CastleRAT payloads inside steganographic JPEG images to evade basic security scans.

Despite public exposure by security vendors, MuddyWater continues to update its installers and deploy fresh malicious lures, maintaining a high operational tempo.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories