Cybersecurity researchers have uncovered fresh evidence linking the Iranian threat group MuddyWater to a Russian-operated malware-as-a-service (MaaS) platform in a new campaign dubbed ChainShell.
The findings highlight a growing trend where state-backed actors rely on commercially developed cybercrime tools to enhance their capabilities.
According to the analysis, investigators identified a direct operational connection between MuddyWater infrastructure and the CastleRAT MaaS ecosystem, operated by a Russian-speaking threat group known as TAG-150.
This link was established through multiple technical artifacts, including command-and-control (C2) servers, malware samples, and shared campaign identifiers.
One of the most critical discoveries was a PowerShell script named reset.PS1, found on a compromised server associated with MuddyWater.
This script deploys a previously undocumented JavaScript-based malware called ChainShell, which uses blockchain technology to retrieve its C2 infrastructure dynamically.
Researchers also observed that MuddyWater used multiple builds of CastleRAT, hidden within steganographic image files.
These payloads included unique identifiers tied to the MaaS platform, confirming that the group is likely a customer rather than the malware’s developer.

Shift Toward Hybrid Cyber Operations
The campaign signals a strategic shift in MuddyWater’s operations. Historically, the group relied on custom PowerShell tools and legitimate remote management software.
However, by adopting MaaS platforms, they now gain access to advanced features such as hidden virtual network computing (HVNC), credential theft, and resilient command-and-control mechanisms.

ChainShell itself introduces a new level of stealth. Instead of relying on traditional servers, it uses blockchain smart contracts to locate its C2 endpoints, making takedowns significantly more difficult.
Additionally, the malware operates as a “thin shell,” executing commands delivered remotely rather than containing built-in malicious functions.
The campaign primarily targets Israeli infrastructure, including government, defense, and technology sectors.
Evidence from the exposed server included Farsi-language comments and lists of Israeli IP ranges, reinforcing attribution to Iranian operators.
Another key finding involves code-signing certificates used across the attack chain.

These certificates, previously linked to known MuddyWater tools, were also used to sign malware components associated with the MaaS platform.
This overlap provides strong attribution evidence tying the campaign to the group.
Security experts warn that the blending of state-sponsored espionage with cybercriminal services complicates detection and attribution.
Jumpsec Organizations may initially mistake such attacks for routine cybercrime, delaying an appropriate response.
The research underscores a broader evolution in cyber threats, where nation-state actors increasingly adopt off-the-shelf tools to accelerate operations.
For defenders, this means facing more sophisticated attacks that combine geopolitical intent with scalable, commercially available malware capabilities.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.