TLP:CLEAR — Attribution Analysis

Really Muddy Waters

Refuting the Seedworm Attribution of Commodity MaaS — Companion analysis to the ClixFlare ClickFix Campaign Technical Report

SubjectSeedworm / MuddyWater attribution of CastleRAT, Tsundere Bot, and ClixFlare infrastructure
AssessmentAttribution is incorrect as stated — commodity MaaS misidentified as Iranian state capability
ConfidenceHIGH
Last UpdatedJuly 2026

1. Executive Summary

In March 2026, Symantec/Broadcom attributed malware found on U.S. and Canadian networks to Seedworm/MuddyWater, an Iranian MOIS cyber espionage unit.[1] This attribution was echoed by Cisco Talos[2], Check Point[3], Rapid7[4], CyberProof[5], and JUMPSEC[6], resulting in ClixFlare delivery infrastructure (zhivachkapro[.]com) and commodity MaaS payloads (CastleRAT, Tsundere Bot, Stagecomp/Darkcomp) being labeled "Iranian state capability" across seven vendor publications.

This document demonstrates that:

  1. Every attributed IOC is commodity malware — independently identified by eSentire[8], Recorded Future, vx-underground, ThreatDown, and Red Canary, with no APT attribution, spanning August 2025 through January 2026 — 7+ months before Symantec's attribution.
  2. The sole technical link (code-signing certificates) is a purchasable criminal service — documented by Microsoft's Fox Tempest MSaaS research ($5k–$9k per certificate).[9]
  3. CastleRAT is Russian-developed MaaS (TAG-150) with Russian developer strings, CIS locale exclusion, and a multi-tenant panel. JUMPSEC explicitly assesses MuddyWater as a customer, not the developer.[6]
  4. The "Smokest" campaign JWT used as the primary attribution chain was found in commodity Amadey distribution via TopWebComics fake installers two months before it appeared on an Iranian-attributed server.
  5. The real MuddyWater espionage operation (documented by Ctrl-Alt-Intel[7]) uses custom Farsi C2 frameworks, Fortinet exploitation, and targets Middle Eastern government/aviation — bearing no resemblance to ClixFlare.
  6. Iranian actors consuming commodity Russian malware is a documented historical pattern — the Handala group used Rhadamanthys with purchased certificates in 2023–2024.

2. Origin: Symantec/Broadcom (March 5, 2026)

The Seedworm attribution originates from Symantec/Broadcom (Threat Hunter Team), published March 5, 2026.[1] Symantec found two malware families on the networks of a U.S. bank, airport, software company (Israeli operations), and a Canadian non-profit:

Symantec's attribution logic:

"The Donald Gay certificate has been used previously to sign malware linked to Seedworm… The Stagecomp and the Darkcomp malware have been linked to Seedworm by vendors including Google, Microsoft and Kaspersky. While this malware wasn't seen on the targeted networks, the use of the same certificates suggests the same actor — namely Seedworm — was behind the activity."[1]

The entire attribution hangs on a single code-signing certificate ("Donald Gay") previously used to sign Stagecomp/Darkcomp, which Symantec claims were "linked to Seedworm by vendors including Google, Microsoft and Kaspersky." However, this prior attribution is uncitable from public sources. "Stagecomp" and "Darkcomp" are Symantec's own detection names (Trojan.Stagecomp, Trojan.Darkcomp). No Google/Mandiant, Microsoft, or Kaspersky publication attributing them to MuddyWater/Seedworm can be found predating this blog post. The documented MuddyWater malware catalog (POWERSTATS, SHARPSTATS, PowGoop, Mori, Small Sieve, STARWHALE, MuddyViper, Fooder, RustyWater, DCHSpy) does not include Stagecomp or Darkcomp. Every secondary source repeating this claim cites Symantec 2026 — the claim is circular.

If the prior Stagecomp/Darkcomp → Seedworm attribution cannot be independently verified, the entire chain collapses: the "Donald Gay" certificate signed multiple things, but the assertion that those things belong to Seedworm is an uncitable appeal to authority.


3. Pre-Attribution History: CastleRAT Was Commodity for 7+ Months

Before Symantec named anything "Dindoor" in March 2026, the same malware family had been independently discovered and documented as commodity criminal malware — with no APT attribution:

eSentire (August 2025) published "New Botnet Emerges from the Shadows: NightshadeC2,"[8] documenting a botnet delivered via ClickFix initial access. The payload uses the window class name "IsabellaWine" — the same hardcoded MaaS template identifier JUMPSEC later found in CastleRAT builds. eSentire documented C and Python variants with HVNC, keylogging, clipboard harvesting, and browser credential theft. The Python variant was assessed as likely LLM-converted. No APT attribution.

Recorded Future (September 2025) began tracking the MaaS platform as TAG-150, identifying CastleRAT as a modular Russian-speaking criminal service.[11]

vx-underground (January 18, 2026) independently discovered the same malware via a "TopWebComics" MSI. Researchers collaboratively reversed the chain: MSI → obfuscated JS → PS1 → Python (PyArmor) → JPEG steganography → CastleRAT payload. vx-underground named the JS component "Smokest Stealer" and called it "a very silly malware sample." No APT attribution.

ffforward/@TheAnalyst (January 19, 2026) corrected the naming: "Smokest might not be a good name, its likely just a campaign indicator." ffforward traced the broader delivery chain — Fake OBS → Donut → Amadey → Various MSI → PowerShell — with downloads of Petuhon.zip (Russian wordplay on "Python") and Smokest120.zip (Build 120) from 172.86.123[.]222.

The decoded JWT from the MSI reveals the full MaaS customer config:

{
  "campaignId": "75cbe18653d52372",
  "campaignName": "Smokest",
  "campaignUrl": "smokest",
  "configId": "8752e5472b9a3a80",
  "proxies": ["http://sharecodepro[.]com"],
  "userId": "bb47c0615477a877",
  "userNote": "topwebcomics",
  "iat": 1768623552,
  "exp": 2084199552
}
Key finding: This is the exact JWT that JUMPSEC[6] later uses as their primary MuddyWater attribution chain — same campaignId, same userId. The userNote is "topwebcomics" — a customer note for a comic book website fake installer campaign. Build 120 was being distributed through Amadey in January 2026, two months before JUMPSEC found it on an Iranian-attributed server. The "Smokest" identity is a TAG-150 MaaS customer configuration, not an Iranian espionage campaign.

The malware was independently identified as commodity criminal tooling by eSentire[8], Recorded Future[11], vx-underground, ThreatDown[10], and Red Canary — spanning August 2025 through January 2026 — before Symantec rebranded it "Dindoor" and attributed it to an Iranian state intelligence unit.[1]


4. The Attribution Cascade

4.1 Echoes: Talos, Check Point, Ctrl-Alt-Intel, JUMPSEC, CyberProof

Cisco Talos (March 10, 2026) echoed Symantec's findings in a blog covering Middle East cyber activity,[2] adding ClixFlare domains to the IOC list without independent attribution analysis:

hxxps://iuumfgrrnuhb[.]zhivachkapro[.]com/pobor
hxxp://terymar[.]com/install/Spf.ps1
Elvenforest[.]s3.us-east-005.backblazeb2[.]com
Uppdatefile[.]com
Gitempire[.]s3.us-east-005.backblazeb2[.]com
Moonzonet[.]com
Serialmenot[.]com

Check Point Research (March 11, 2026) published "Iranian MOIS Actors & the Cyber Crime Connection,"[3] taking a more nuanced position: they explicitly acknowledge CastleLoader is MaaS and frame the relationship as MOIS actors using criminal tools. Their evidence is the same shared certificates, which they themselves note could indicate "common certificate sources or resale." Check Point also reveals that Tsundere Bot supports both Node.js and Deno runtimes.

Rapid7 (July 2026) published "Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware,"[4] attributing a Chaos ransomware incident to MuddyWater as a "false flag masquerade." Their evidence: the attacker used Stagecomp (ms_upd.exe, 24857fe8...) to download Darkcomp (Game.exe, 1319d474...), both signed with the "Donald Gay" certificate, with C2 at moonzonet[.]com. These are the exact hashes from Symantec's IOC list. Rapid7 does not address the possibility that the certificate was purchased from a signing service.

Unattributed security researcher (January 2026) observed the same Stagecomp → Darkcomp chain independently — two months before Symantec's attribution: QuickAssist social engineering via dntix[.]com, initial binary ms_upd.exe connecting to moonzonet[.]com, dropping MessageBox.exeMozilla-fbbf0ab6.exe which contacted uploadfiler[.]com. The researcher described it as "interesting chain of activity" — no APT attribution.

Ctrl-Alt-Intel (March 4, 2026) published "MuddyWater Exposed: Inside an Iranian APT operation,"[7] documenting an exposed VPS (157.20.182[.]49) in the Netherlands. Ctrl-Alt-Intel's MuddyWater attribution for the espionage operation on this server is credible, based on:

However, alongside these custom espionage tools, the server also contained reset.ps1 — Tsundere Bot / ChainShell (Node.js + ethers + ws, EtherHiding). This is a TAG-150 commodity tool sitting alongside custom espionage implants. Multiple explanations exist:

  1. Customer: MuddyWater purchased a TAG-150 license and staged it for deployment.
  2. Research/inspiration: Operators found publicly discussed samples on X and downloaded them to evaluate.
  3. Shared infrastructure: Other actors on the same hosting may have left artifacts.
In all three cases, finding Tsundere Bot on a MuddyWater server does not make Tsundere Bot a MuddyWater tool, any more than finding Cobalt Strike on an APT29 server makes Cobalt Strike Russian. MuddyWater has their own C2 frameworks (KeyC2, PersianC2) — the presence of a commodity tool alongside custom implants demonstrates consumption, not ownership.

JUMPSEC (April 7, 2026) published "ChainShell: MuddyWater's Russian MaaS Link,"[6] analyzing the same server. JUMPSEC's primary attribution chain is a JWT trace: Amy Cherne cert → MSI → serialmenot[.]com/mv2/<JWT> with campaignId: 75cbe18653d52372, campaignName: "Smokest", userID: bb47c0615477a877.

This JWT chain is significantly weakened by prior evidence neither JUMPSEC nor Ctrl-Alt-Intel addressed. The same JWT was extracted from a TopWebComics fake installer MSI in January 2026. The userNote is literally "topwebcomics". Build 120 was being distributed through Amadey (a commodity loader-as-a-service) — this is commodity financially-motivated distribution, not espionage tradecraft.

JUMPSEC's own conclusions support the commodity thesis:[6]

JUMPSEC also repeats Symantec's uncitable claim that StageComp was "attributed by Google, Microsoft, and Kaspersky," and lists Google TAG, Microsoft TI, and Kaspersky GReAT in their acknowledgements — suggesting these may be private intelligence shares, not public publications.

Implication for ClixFlare: Ctrl-Alt-Intel[7] demonstrates that real MuddyWater espionage (Fortinet exploitation, OWA spraying, custom Farsi C2s, Middle Eastern government targets) looks nothing like ClixFlare (WordPress ClickFix, Five Eyes consumers, commodity MaaS payloads).

CyberProof (July 2026) published "Iranian APT Seedworm Targets Global Organizations via Microsoft Teams,"[5] attributing a Teams intrusion to Seedworm. CyberProof's attribution rests entirely on matching artifacts against Talos/Symantec IOC lists — circular inheritance.

4.2 The Certificate Problem

The code-signing certificates remain the primary technical link. Microsoft published "Exposing Fox Tempest: A malware-signing service operation,"[9] documenting a Malware-Signing-as-a-Service (MSaaS) operation (signspace[.]cloud) selling certificates for $5,000–$9,000 USD. Fox Tempest's customers include ransomware affiliates linked to INC, Qilin, Akira, and Rhysida.

The "Amy Cherne" and "Donald Gay" certificates are consistent with certificates purchased from a signing service like Fox Tempest. Shared certificates prove shared suppliers, not shared operators.

5. Counter-Evidence Summary

Every "Seedworm" IOC published by Symantec[1] and echoed by Talos[2] has been independently identified as commodity cybercrime:

Vendor LabelActual IdentityIdentified By
"Dindoor" (bd8203ab...)CastleRAT (clickzpaqkvba.msi)ThreatDown[10]
"Seedworm Loader Script" (29b777e7...)Tsundere Bot installer (Spf.ps1)Proofpoint, Kaspersky
serialmenot[.]comCastleRAT JS loader C2ThreatDown[10]
zhivachkapro[.]comClixFlare ClickFix C2ClixFlare report
"Amy Cherne" / "Donald Gay" certsCommodity signing serviceMicrosoft (Fox Tempest)[9]

6. Attribution Cascade Timeline

eSentire (Aug 2025): Discovers "NightshadeC2" (=CastleRAT) via ClickFix delivery [8] → Documents "IsabellaWine" window class — same MaaS template ID in CastleRAT builds → No APT attribution. Recorded Future (Sep 2025): Tracks MaaS platform as TAG-150. Russian criminal service. [11] vx-underground (Jan 2026): Finds "Smokest Stealer" via TopWebComics MSI → "Smokest" = same campaign identity JUMPSEC later attributes to MuddyWater → Called it "a very silly malware sample." No APT attribution. Unattributed researcher (Jan 2026): Observes Stagecomp → Darkcomp via QuickAssist → No APT attribution — "interesting chain of activity" Rapid7 (early 2026): Encounters same chain in Chaos RaaS incident [4] ——— ATTRIBUTION EVENT ——— Symantec (Mar 5): Names it "Dindoor"/"Fakeset", attributes to Seedworm [1] → Via "Donald Gay" cert; claims uncitable prior attribution Talos (Mar 10): Echoes Symantec, no independent analysis [2] ThreatDown (Mar 10): Identifies same malware as CastleRAT. No APT attribution. [10] Check Point (Mar 11): "MOIS cyber crime connection" [3] Ctrl-Alt-Intel (Mar 4): Credible MuddyWater VPS, but commodity tool alongside custom ones [7] JUMPSEC (Apr 7): "MuddyWater is a CUSTOMER" — JWT weakened by prior Amadey distribution [6] Microsoft (May 19): Fox Tempest MSaaS — certificates are commodity [9] Rapid7 (Jul): Chaos RaaS writeup — circular cert attribution [4] CyberProof (Jul): Attribution inherited entirely from IOC lists [5] Result: Russian commodity MaaS labeled "Iranian state capability" across seven vendor publications. Five independent observers saw the same tooling with NO APT attribution.

7. Reductio ad Absurdum

If the combined vendor attribution is taken at face value, a single MOIS subordinate element (MuddyWater) would simultaneously be:

  1. Operating ClixFlare — a mass WordPress ClickFix IAB platform targeting Five Eyes consumers
  2. Developing and selling CastleRAT — a commodity MaaS infostealer sold via panel
  3. Developing and selling Tsundere Bot — a separate Node.js MaaS botnet used by Russian cybercriminals
  4. Purchasing code-signing certificates from the same MSaaS vendors used by Chaos, INC, Qilin, and Akira affiliates
  5. Operating as a Chaos RaaS affiliate — deploying ransomware against U.S. companies[4]
  6. Operating as a Qilin RaaS affiliate — attacking an Israeli hospital[3]
  7. Running Teams social engineering under "Sarah Wilson" to deliver CastleRAT[5]
  8. Maintaining actual espionage operations against Middle Eastern government targets
The fundamental attribution error is treating usage as ownership. CastleRAT is a Russian-developed MaaS product (TAG-150) with Russian developer strings, CIS locale exclusion, a multi-tenant panel, and customers including LeakNet ransomware. JUMPSEC[6] explicitly confirms MuddyWater is a customer, not the developer. By the same logic, Cobalt Strike would be a Chinese APT tool because Chinese groups use it. No vendor would accept that framing for Western offensive tooling — but because the geopolitical narrative fits, a Russian criminal MaaS product becomes "Iranian state capability."

The simpler explanation: multiple unrelated criminal actors purchased the same commodity malware, the same commodity signing certificates, and in some cases obtained initial access through the same commodity IAB (ClixFlare). The "Donald Gay" certificate is not a fingerprint — it is a receipt.


8. Historical Precedent: Iranian Actors as Commodity MaaS Customers

The pattern of Iranian state-affiliated actors consuming Russian commodity malware and purchasing code-signing certificates predates the CastleRAT/ClixFlare attribution by years.

8.1 Handala Group — Rhadamanthys + Purchased Certificates (2023–2026)

The Handala group (MOIS-linked Iranian hacktivists) conducted destructive wiper operations against Israeli targets using commodity Russian malware for intelligence collection, followed by custom destructive tools.

F5UPDATER Campaign (2023):

  1. F5UPDATER.exe — signed with "Skytec Global Ltd" certificate (SSL.com, 2023-12-17, subsequently revoked).
  2. Handala.exe runs first — deploys Rhadamanthys infostealer via Asgard Protector loader (AV enumeration, binary fragment reassembly via Naples.pif, process hollowing via WerFault.exe).
  3. Hatef.exe runs second — the actual wiper (ConfirmDeleteFiles).

INCD Impersonation (April 2024): Handala impersonated Israel's National Cyber Directorate via incd[.]org[.]il, delivering encrypted ZIP → WSF → Asgard Protector → Rhadamanthys again.

8.2 Pattern Summary

CampaignIranian ActorCommodity Tool (Russian)CertificateCustom Tool
F5UPDATER (2023)HandalaRhadamanthys (Asgard Protector)"Skytec Global Ltd" (purchased, revoked)Hatef wiper
INCD impersonation (2024)HandalaRhadamanthys (Asgard Protector)Non-reused CF domainsWiper
Ctrl-Alt-Intel server (2026)MuddyWaterTsundere Bot / ChainShell (TAG-150)"Amy Cherne" / "Donald Gay"KeyC2, PersianC2
CastleRAT MaaS (2025–2026)Attributed to MuddyWaterCastleRAT, Stagecomp/Darkcomp (TAG-150)"Amy Cherne" / "Donald Gay"None identified

The consistent pattern: Iranian actors purchase commodity Russian malware for collection and purchase code-signing certificates from criminal MSaaS vendors. Their custom tools (wipers, Farsi C2 frameworks) are separate and distinct. When vendors attribute the commodity tools to the Iranian actors as if they developed them, they are conflating consumption with ownership.


9. Confidence Assessment

HIGH — The Seedworm attribution is incorrect as stated. Every IOC has been independently identified as commodity malware by other vendors, and the sole technical link (code-signing certificates) is a documented commodity service.

HIGHzhivachkapro[.]com is ClixFlare infrastructure.

MODERATE — Seedworm may have used ClixFlare-delivered access as an entry point at specific targets, but the malware itself (CastleRAT, Tsundere Bot, Stagecomp/Darkcomp) is commodity MaaS available to any buyer.


10. Cross-Vendor IOC Overlap

All hashes and domains below have been attributed to Seedworm/MuddyWater by one or more vendors. We assess these are commodity MaaS artifacts, not APT-exclusive tooling.

10.1 Cross-Vendor Hash Overlap

SHA-256SymantecTalosThreatDownCheck PointRapid7CyberProof
bd8203ab...DindoorDindoorCastleRAT MSI
2a00705c...DindoorCastleRAT dropperCastleRAT dropper
2a09bbb3...DindoorDinDoor/Tsundere
077ab28d...FakesetFakeSet/CastleLoader
24857fe8...StagecompStageCompms_upd.exe
a92d28f1...StagecompDIDS.exe
3df9dcc4...DarkcompWebView2.exe
1319d474...DarkcompGame.exe
29b777e7..."Seedworm Loader"
500ee774...CastleRAT MSI (Teams)

10.2 Cross-Vendor Domain/Infrastructure Overlap

IndicatorSymantecTalosThreatDownRapid7Red CanaryCyberProof
serialmenot[.]com✓ (CastleRAT C2)
moonzonet[.]com✓ (Darkcomp C2)✓ (Darkcomp C2)
uploadfiler[.]com✓ (config C2)✓ (Darkcomp C2)
zhivachkapro[.]com✓ (CastleRAT ClickFix)
gitempire...backblazeb2[.]com
elvenforest...backblazeb2[.]com
uppdatefile[.]com

10.3 Code-Signing Certificates

Field"Donald Gay""Amy Cherne"
IssuerMicrosoft ID Verified CS AOC CA 02Microsoft ID Verified CS AOC CA 02
ThumbprintB674578D4BDB24CD58BF2DC884EAA658B7AA250C0902D7915A19975817EC1CCB0F2F6714AED19638
Serial3300079A51C7063E66053D229B000000079A51330007F1068F41BF0F662A03B500000007F106
StatusRevoked (time-invalid)Revoked (time-invalid)
SignsStagecomp, Darkcomp, Fakeset, DindoorFakeset, Dindoor
Counter-evidenceFox Tempest MSaaS sells equivalent certs for $5k–$9k[9]Same

11. Per-Vendor IOC Lists

11.1 Symantec/Broadcom[1] (March 5, 2026)

Trojan.Dindoor (CastleRAT):

SHA-256Notes
0f9cf1cf8d641562053ce533aaa413754db88e60404cab6bbaa11f2b2491d542
1d984d4b2b508b56a77c9a567fb7a50c858e672d56e8cf7677a1fca5c98c95d1
2a00705cfd3c15cf8913e9eb4e23968efd06f1feceaef9987d26c5518887d043Also ThreatDown CastleRAT dropper[10]
2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5Also Check Point DinDoor/Tsundere[3]
42a5db2a020155b2adb77c00cbe6c6ad27c2285d8c6114679d9d34137e870b3f
7467f326677a4a2c8576e71a832e297e794ea00e9b67c4fcbe78b5aec697cec4
7c30c16e7a311dc0cdb1cdfd9ea6e502f44c027328dbe7d960b9bcd85ccf5eef
b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0
bd8203ab88983bc081545ff325f39e9c5cd5eb6a99d04ae2a6cf862535c9829aAlso ThreatDown CastleRAT MSI[10], Talos[2]
c7cf1575336e78946f4fe4b0e7416b6ebe6813a1a040c54fb6ad82e72673478e

Trojan.Fakeset (CastleLoader):

SHA-256Notes
077ab28d66abdafad9f5411e18d26e87fe43da1410ee8fe846bd721ab0cb52deAlso Check Point FakeSet/CastleLoader[3]
15061036c702ad92b56b35e42cf5dc334597e7311e98d2fdd3815a69ac3b1d84
2b7d8a519f44d3105e9fde2770c75efb933994c658855dca7d48c8b4897f81e6
4aef998e3b3f6ca21c78ed71732c9d2bdcc8a4e0284f51d7462c79d446fbc7be
64263640a6fdeb2388bca2e9094a17065308cf8dcb0032454c0a71d9b78327eb
64cf334716f15da1db7981fad6c81a640d94aa1d65391ef879f4b7b6edf6e7f1
74db1f653da6de134bdc526412a517a30b6856de9c3e5d0c742cb5fe9959ad0d
94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444
a4bd1371fe644d7e6898045cc8e7b5e1562bdfd0e4871d46034e29a22dec6377
a5d4d6be3bfe0cba23fe6b44984b5fc9c7c7e10030be96120bb30da0f2545d4c
ddceade244c636435f2444cd4c4d3dc161981f3af1f622c03442747ecef50888

Trojan.Stagecomp / Trojan.Darkcomp:

SHA-256TypeNotes
24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14StagecompAlso Rapid7[4] ms_upd.exe, Check Point[3]
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0StagecompAlso Rapid7[4] DIDS.exe
3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90DarkcompAlso Rapid7[4] WebView2.exe
1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6DarkcompAlso Rapid7[4] Game.exe

Symantec domains:

IndicatorTypeNotes
gitempire.s3.us-east-005.backblazeb2[.]comBackblaze B2Fakeset staging (also in Talos[2])
elvenforest.s3.us-east-005.backblazeb2[.]comBackblaze B2Fakeset staging (also in Talos[2])
uppdatefile[.]comDomainAlso in Talos[2]
serialmenot[.]comDomainCastleRAT C2 (also in Talos, ThreatDown, CyberProof)
moonzonet[.]comDomainAlso in Talos[2], Rapid7[4]

11.2 Talos[2] (March 10, 2026)

IndicatorTypeNotes
hxxps://iuumfgrrnuhb[.]zhivachkapro[.]com/poborURLClixFlare C2, different endpoint from /cobor
terymar[.]comDomain/install/Spf.ps1 — Node.js 18.17.0 + EtherHiding
29b777e7c5470d557e34f3b7b76d2ee291c2dfe7fbaee72821b53eb50a4062c8SHA-256Spf.ps1Tsundere Bot installer

11.3 ThreatDown[10] (March 10, 2026 — no APT attribution)

IndicatorTypeNotes
dsennbuappec[.]zhivachkapro[.]comURLCastleRAT ClickFix C2
qzfbxajdtw[.]zhivachkapro[.]com/poborURLCastleRAT dropper delivery
serialmenot[.]comDomainCastleRAT JS loader C2
172[.]86.123.222IPPython loader C2
23[.]94.145.120IPCastleRAT C2
2a00705cfd3c15cf8913e9eb4e23968efd06f1feceaef9987d26c5518887d043SHA-256CastleRAT dropper (PS1)
bd8203ab88983bc081545ff325f39e9c5cd5eb6a99d04ae2a6cf862535c9829aSHA-256clickzpaqkvba.msi — also Symantec[1]
a4787a42070994b7f1222025828faf9b153710bb730e58da710728e148282e28SHA-256CastleRAT PE payload
VirtualSmokestGuy666SchtaskCastleRAT persistence
CFBAT.jpgFileSteganographic payload container
clickzpaqkvba.msiFileCastleRAT MSI installer

11.4 Rapid7[4] (July 2026 — Chaos RaaS)

IndicatorTypeNotes
24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14SHA-256ms_upd.exe (Stagecomp)
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0SHA-256DIDS.exe (Stagecomp)
1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6SHA-256Game.exe (Darkcomp)
3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90SHA-256WebView2.exe (Darkcomp)
c86ab27100f2a2939ac0d4a8af511f0a1a8116ba856100aae03bc2ad6cb0f1e0SHA-256visualwincomp.txt (encrypted C2 config)
a47cd0dc12f0152d8f05b79e5c86bac9231f621db7b0e90a32f87b98b4e82f3aSHA-256WebView2Loader.dll
moonzonet[.]comDomainDarkcomp C2
uploadfiler[.]comDomainC2 from encrypted config
adm-pulse[.]comDomainQuick Assist themed phishing
172[.]86.126.208IPC2 hosting Stagecomp
116[.]203.208.186IPContacted by renamed pythonw.exe
Donald Gay certThumbprint B674578D...Same cert as Symantec/Check Point

11.5 Red Canary (January 2026 — no APT attribution)

IndicatorTypeNotes
dntix[.]comDomainQuickAssist social engineering lure
ms_upd.exeFileStagecomp — same as Rapid7[4], Symantec[1]
moonzonet[.]comDomainDarkcomp C2
MessageBox.exeMozilla-fbbf0ab6.exeFileDarkcomp RAT persistence path
uploadfiler[.]comDomainDarkcomp C2
144[.]172.111.233IPReverse SSH tunnel endpoint
asuedulimitSSH userReverse tunnel authentication (-R 54321)

11.6 CyberProof[5] (July 2026 — attribution cascaded from Talos)

IndicatorTypeNotes
seqhelpsitdevsupportops[.]onmicrosoft.comM365 tenantTeams social engineering ("Sarah Wilson")
500ee77471669175b359bf57384291cab791200191d0e5a5bb190da53ccb30eeSHA-256update_ms.msi — CastleRAT MSI
dd3.filedwnl[.]topDomainSecondary payload server
dd4.filedwnl[.]topDomainSecondary payload server
140[.]82.18.48IPC2
serialmenot[.]comDomainCastleRAT C2
Falcon_module63.vbsFileCastleRAT component
tango13.ps1FilePowerShell downloader

12. Conclusion

The Seedworm/MuddyWater attribution of CastleRAT, Tsundere Bot, and ClixFlare infrastructure represents a systemic failure in threat intelligence methodology — not a failure of any single vendor, but the cumulative effect of an attribution cascade where each publication reinforced the last without independent verification of the foundational claim.

The sequence is clear: Symantec attributed commodity malware to an Iranian state unit based on a shared code-signing certificate and an uncitable prior attribution. Talos echoed it. Check Point, Rapid7, CyberProof, and JUMPSEC each inherited the attribution through IOC matching, adding their own incidents to the same pile without questioning the base layer. By July 2026, seven vendor publications had collectively transformed a Russian criminal MaaS platform into "Iranian state capability" — while five independent observers who encountered the same tooling earlier saw nothing but commodity cybercrime.

The irony is that JUMPSEC — whose analysis is the most technically rigorous — explicitly reached the correct conclusion: MuddyWater is a customer of TAG-150, not its developer.[6] Yet even this finding was framed as "MuddyWater's Russian MaaS Link" rather than what it actually demonstrates: that the TAG-150 ecosystem is a multi-tenant criminal service whose customer list tells you nothing about who operates it.

The practical consequences are significant. Defenders who ingest Seedworm IOC feeds now have commodity MaaS infrastructure mapped to an Iranian state actor, generating false positives whenever any TAG-150 customer — LeakNet ransomware, Chaos RaaS affiliates, random fake-installer campaigns — triggers the same indicators. The attribution has not improved anyone's security posture; it has degraded it.

The correct framing: zhivachkapro[.]com is ClixFlare — a commodity initial access broker. CastleRAT and Tsundere Bot are TAG-150 — a Russian criminal MaaS platform. The "Amy Cherne" and "Donald Gay" certificates are receipts from a signing service, not fingerprints of a state actor. MuddyWater may well be one of many customers who purchased access through these services — but the services themselves, and the infrastructure that delivers them, are not Iranian state operations.


References

  1. Symantec/Broadcom — "Seedworm: Iranian Hackers Target Telecoms, IT, and Utilities" (March 5, 2026). https://www.security.com/threat-intelligence/iran-cyber-threat-activity-us
  2. Cisco Talos — "Talos Developing Situation in the Middle East" (March 10, 2026). https://blog.talosintelligence.com/talos-developing-situation-in-the-middle-east/
  3. Check Point Research — "Iranian MOIS Actors & the Cyber Crime Connection" (March 11, 2026). https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/
  4. Rapid7 — "Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware" (July 2026). https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/
  5. CyberProof — "Iranian APT Seedworm Targets Global Organizations via Microsoft Teams" (July 2026). https://www.cyberproof.com/blog/iranian-apt-seedworm-targets-global-organizations-via-microsoft-teams/
  6. JUMPSEC — "ChainShell: MuddyWater's Russian Criminal Infrastructure" (April 7, 2026). https://www.jumpsec.com/guides/chainshell-muddywater-russian-criminal-infrastructure/
  7. Ctrl-Alt-Intel — "MuddyWater Exposed: Inside an Iranian APT operation" (March 4, 2026). https://ctrlaltintel.com/research/MuddyWater/
  8. eSentire — "New Botnet Emerges from the Shadows: NightshadeC2" (August 2025). https://www.esentire.com/blog/new-botnet-emerges-from-the-shadows-nightshadec2
  9. Microsoft — "Exposing Fox Tempest: A malware-signing service operation" (May 19, 2026).
  10. ThreatDown/Malwarebytes — CastleRAT analysis (March 10, 2026).
  11. Recorded Future — TAG-150 tracking (September 2025).
  12. ESET — "MuddyWater: Snakes by the riverbank" (December 2025).
  13. Group-IB — "Operation Olalampo: Inside MuddyWater's Latest Campaign" (February 2026).