Researchers Link MuddyWater To Russian MaaS In Latest ChainShell Operation

Cybersecurity researchers have uncovered fresh evidence linking the Iranian threat group MuddyWater to a Russian-operated malware-as-a-service (MaaS) platform in a new campaign dubbed ChainShell.

The findings highlight a growing trend where state-backed actors rely on commercially developed cybercrime tools to enhance their capabilities.

According to the analysis, investigators identified a direct operational connection between MuddyWater infrastructure and the CastleRAT MaaS ecosystem, operated by a Russian-speaking threat group known as TAG-150.

This link was established through multiple technical artifacts, including command-and-control (C2) servers, malware samples, and shared campaign identifiers.

One of the most critical discoveries was a PowerShell script named reset.PS1, found on a compromised server associated with MuddyWater.

This script deploys a previously undocumented JavaScript-based malware called ChainShell, which uses blockchain technology to retrieve its C2 infrastructure dynamically.

Researchers also observed that MuddyWater used multiple builds of CastleRAT, hidden within steganographic image files.

These payloads included unique identifiers tied to the MaaS platform, confirming that the group is likely a customer rather than the malware’s developer.

ChainShell’s Operational Flow (Source: jumpsec)
ChainShell’s Operational Flow (Source: jumpsec)

Shift Toward Hybrid Cyber Operations

The campaign signals a strategic shift in MuddyWater’s operations. Historically, the group relied on custom PowerShell tools and legitimate remote management software.

However, by adopting MaaS platforms, they now gain access to advanced features such as hidden virtual network computing (HVNC), credential theft, and resilient command-and-control mechanisms.

MuddyWater Operations Timeline (Source: jumpsec)
MuddyWater Operations Timeline (Source: jumpsec)

ChainShell itself introduces a new level of stealth. Instead of relying on traditional servers, it uses blockchain smart contracts to locate its C2 endpoints, making takedowns significantly more difficult.

Additionally, the malware operates as a “thin shell,” executing commands delivered remotely rather than containing built-in malicious functions.

The campaign primarily targets Israeli infrastructure, including government, defense, and technology sectors.

Evidence from the exposed server included Farsi-language comments and lists of Israeli IP ranges, reinforcing attribution to Iranian operators.

Another key finding involves code-signing certificates used across the attack chain.

MuddyWater are using different JWT credentials for the serialmenot.com C2 (Source: jumpsec)
MuddyWater are using different JWT credentials for the serialmenot.com C2 (Source: jumpsec)

These certificates, previously linked to known MuddyWater tools, were also used to sign malware components associated with the MaaS platform.

This overlap provides strong attribution evidence tying the campaign to the group.

Security experts warn that the blending of state-sponsored espionage with cybercriminal services complicates detection and attribution.

Jumpsec Organizations may initially mistake such attacks for routine cybercrime, delaying an appropriate response.

The research underscores a broader evolution in cyber threats, where nation-state actors increasingly adopt off-the-shelf tools to accelerate operations.

For defenders, this means facing more sophisticated attacks that combine geopolitical intent with scalable, commercially available malware capabilities.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories