Refuting the Seedworm Attribution of Commodity MaaS — Companion analysis to the ClixFlare ClickFix Campaign Technical Report
| Subject | Seedworm / MuddyWater attribution of CastleRAT, Tsundere Bot, and ClixFlare infrastructure |
| Assessment | Attribution is incorrect as stated — commodity MaaS misidentified as Iranian state capability |
| Confidence | HIGH |
| Last Updated | July 2026 |
In March 2026, Symantec/Broadcom attributed malware found on U.S. and Canadian networks to Seedworm/MuddyWater, an Iranian MOIS cyber espionage unit.[1] This attribution was echoed by Cisco Talos[2], Check Point[3], Rapid7[4], CyberProof[5], and JUMPSEC[6], resulting in ClixFlare delivery infrastructure (zhivachkapro[.]com) and commodity MaaS payloads (CastleRAT, Tsundere Bot, Stagecomp/Darkcomp) being labeled "Iranian state capability" across seven vendor publications.
This document demonstrates that:
The Seedworm attribution originates from Symantec/Broadcom (Threat Hunter Team), published March 5, 2026.[1] Symantec found two malware families on the networks of a U.S. bank, airport, software company (Israeli operations), and a Canadian non-profit:
gitempire, elvenforest).Symantec's attribution logic:
"The Donald Gay certificate has been used previously to sign malware linked to Seedworm… The Stagecomp and the Darkcomp malware have been linked to Seedworm by vendors including Google, Microsoft and Kaspersky. While this malware wasn't seen on the targeted networks, the use of the same certificates suggests the same actor — namely Seedworm — was behind the activity."[1]
The entire attribution hangs on a single code-signing certificate ("Donald Gay") previously used to sign Stagecomp/Darkcomp, which Symantec claims were "linked to Seedworm by vendors including Google, Microsoft and Kaspersky." However, this prior attribution is uncitable from public sources. "Stagecomp" and "Darkcomp" are Symantec's own detection names (Trojan.Stagecomp, Trojan.Darkcomp). No Google/Mandiant, Microsoft, or Kaspersky publication attributing them to MuddyWater/Seedworm can be found predating this blog post. The documented MuddyWater malware catalog (POWERSTATS, SHARPSTATS, PowGoop, Mori, Small Sieve, STARWHALE, MuddyViper, Fooder, RustyWater, DCHSpy) does not include Stagecomp or Darkcomp. Every secondary source repeating this claim cites Symantec 2026 — the claim is circular.
If the prior Stagecomp/Darkcomp → Seedworm attribution cannot be independently verified, the entire chain collapses: the "Donald Gay" certificate signed multiple things, but the assertion that those things belong to Seedworm is an uncitable appeal to authority.
Before Symantec named anything "Dindoor" in March 2026, the same malware family had been independently discovered and documented as commodity criminal malware — with no APT attribution:
eSentire (August 2025) published "New Botnet Emerges from the Shadows: NightshadeC2,"[8] documenting a botnet delivered via ClickFix initial access. The payload uses the window class name "IsabellaWine" — the same hardcoded MaaS template identifier JUMPSEC later found in CastleRAT builds. eSentire documented C and Python variants with HVNC, keylogging, clipboard harvesting, and browser credential theft. The Python variant was assessed as likely LLM-converted. No APT attribution.
Recorded Future (September 2025) began tracking the MaaS platform as TAG-150, identifying CastleRAT as a modular Russian-speaking criminal service.[11]
vx-underground (January 18, 2026) independently discovered the same malware via a "TopWebComics" MSI. Researchers collaboratively reversed the chain: MSI → obfuscated JS → PS1 → Python (PyArmor) → JPEG steganography → CastleRAT payload. vx-underground named the JS component "Smokest Stealer" and called it "a very silly malware sample." No APT attribution.
ffforward/@TheAnalyst (January 19, 2026) corrected the naming: "Smokest might not be a good name, its likely just a campaign indicator." ffforward traced the broader delivery chain — Fake OBS → Donut → Amadey → Various MSI → PowerShell — with downloads of Petuhon.zip (Russian wordplay on "Python") and Smokest120.zip (Build 120) from 172.86.123[.]222.
The decoded JWT from the MSI reveals the full MaaS customer config:
{
"campaignId": "75cbe18653d52372",
"campaignName": "Smokest",
"campaignUrl": "smokest",
"configId": "8752e5472b9a3a80",
"proxies": ["http://sharecodepro[.]com"],
"userId": "bb47c0615477a877",
"userNote": "topwebcomics",
"iat": 1768623552,
"exp": 2084199552
}
campaignId, same userId. The userNote is "topwebcomics" — a customer note for a comic book website fake installer campaign. Build 120 was being distributed through Amadey in January 2026, two months before JUMPSEC found it on an Iranian-attributed server. The "Smokest" identity is a TAG-150 MaaS customer configuration, not an Iranian espionage campaign.The malware was independently identified as commodity criminal tooling by eSentire[8], Recorded Future[11], vx-underground, ThreatDown[10], and Red Canary — spanning August 2025 through January 2026 — before Symantec rebranded it "Dindoor" and attributed it to an Iranian state intelligence unit.[1]
Cisco Talos (March 10, 2026) echoed Symantec's findings in a blog covering Middle East cyber activity,[2] adding ClixFlare domains to the IOC list without independent attribution analysis:
hxxps://iuumfgrrnuhb[.]zhivachkapro[.]com/pobor hxxp://terymar[.]com/install/Spf.ps1 Elvenforest[.]s3.us-east-005.backblazeb2[.]com Uppdatefile[.]com Gitempire[.]s3.us-east-005.backblazeb2[.]com Moonzonet[.]com Serialmenot[.]com
Check Point Research (March 11, 2026) published "Iranian MOIS Actors & the Cyber Crime Connection,"[3] taking a more nuanced position: they explicitly acknowledge CastleLoader is MaaS and frame the relationship as MOIS actors using criminal tools. Their evidence is the same shared certificates, which they themselves note could indicate "common certificate sources or resale." Check Point also reveals that Tsundere Bot supports both Node.js and Deno runtimes.
Rapid7 (July 2026) published "Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware,"[4] attributing a Chaos ransomware incident to MuddyWater as a "false flag masquerade." Their evidence: the attacker used Stagecomp (ms_upd.exe, 24857fe8...) to download Darkcomp (Game.exe, 1319d474...), both signed with the "Donald Gay" certificate, with C2 at moonzonet[.]com. These are the exact hashes from Symantec's IOC list. Rapid7 does not address the possibility that the certificate was purchased from a signing service.
Unattributed security researcher (January 2026) observed the same Stagecomp → Darkcomp chain independently — two months before Symantec's attribution: QuickAssist social engineering via dntix[.]com, initial binary ms_upd.exe connecting to moonzonet[.]com, dropping MessageBox.exe → Mozilla-fbbf0ab6.exe which contacted uploadfiler[.]com. The researcher described it as "interesting chain of activity" — no APT attribution.
Ctrl-Alt-Intel (March 4, 2026) published "MuddyWater Exposed: Inside an Iranian APT operation,"[7] documenting an exposed VPS (157.20.182[.]49) in the Netherlands. Ctrl-Alt-Intel's MuddyWater attribution for the espionage operation on this server is credible, based on:
162.0.230[.]185 previously attributed to MuddyWater by Group-IB[13]; IP 194.11.246[.]101 previously identified by ESET[12] as a MuddyWater C2.However, alongside these custom espionage tools, the server also contained reset.ps1 — Tsundere Bot / ChainShell (Node.js + ethers + ws, EtherHiding). This is a TAG-150 commodity tool sitting alongside custom espionage implants. Multiple explanations exist:
JUMPSEC (April 7, 2026) published "ChainShell: MuddyWater's Russian MaaS Link,"[6] analyzing the same server. JUMPSEC's primary attribution chain is a JWT trace: Amy Cherne cert → MSI → serialmenot[.]com/mv2/<JWT> with campaignId: 75cbe18653d52372, campaignName: "Smokest", userID: bb47c0615477a877.
This JWT chain is significantly weakened by prior evidence neither JUMPSEC nor Ctrl-Alt-Intel addressed. The same JWT was extracted from a TopWebComics fake installer MSI in January 2026. The userNote is literally "topwebcomics". Build 120 was being distributed through Amadey (a commodity loader-as-a-service) — this is commodity financially-motivated distribution, not espionage tradecraft.
JUMPSEC's own conclusions support the commodity thesis:[6]
serialmenot[.]com C2 is multi-tenant. Other threat groups including LeakNet ransomware use the same Deno codebase with different campaign configs.""вернул", "провайдер") and CIS locale exclusion.JUMPSEC also repeats Symantec's uncitable claim that StageComp was "attributed by Google, Microsoft, and Kaspersky," and lists Google TAG, Microsoft TI, and Kaspersky GReAT in their acknowledgements — suggesting these may be private intelligence shares, not public publications.
Implication for ClixFlare: Ctrl-Alt-Intel[7] demonstrates that real MuddyWater espionage (Fortinet exploitation, OWA spraying, custom Farsi C2s, Middle Eastern government targets) looks nothing like ClixFlare (WordPress ClickFix, Five Eyes consumers, commodity MaaS payloads).
CyberProof (July 2026) published "Iranian APT Seedworm Targets Global Organizations via Microsoft Teams,"[5] attributing a Teams intrusion to Seedworm. CyberProof's attribution rests entirely on matching artifacts against Talos/Symantec IOC lists — circular inheritance.
The code-signing certificates remain the primary technical link. Microsoft published "Exposing Fox Tempest: A malware-signing service operation,"[9] documenting a Malware-Signing-as-a-Service (MSaaS) operation (signspace[.]cloud) selling certificates for $5,000–$9,000 USD. Fox Tempest's customers include ransomware affiliates linked to INC, Qilin, Akira, and Rhysida.
Every "Seedworm" IOC published by Symantec[1] and echoed by Talos[2] has been independently identified as commodity cybercrime:
| Vendor Label | Actual Identity | Identified By |
|---|---|---|
"Dindoor" (bd8203ab...) | CastleRAT (clickzpaqkvba.msi) | ThreatDown[10] |
"Seedworm Loader Script" (29b777e7...) | Tsundere Bot installer (Spf.ps1) | Proofpoint, Kaspersky |
serialmenot[.]com | CastleRAT JS loader C2 | ThreatDown[10] |
zhivachkapro[.]com | ClixFlare ClickFix C2 | ClixFlare report |
| "Amy Cherne" / "Donald Gay" certs | Commodity signing service | Microsoft (Fox Tempest)[9] |
If the combined vendor attribution is taken at face value, a single MOIS subordinate element (MuddyWater) would simultaneously be:
The simpler explanation: multiple unrelated criminal actors purchased the same commodity malware, the same commodity signing certificates, and in some cases obtained initial access through the same commodity IAB (ClixFlare). The "Donald Gay" certificate is not a fingerprint — it is a receipt.
The pattern of Iranian state-affiliated actors consuming Russian commodity malware and purchasing code-signing certificates predates the CastleRAT/ClixFlare attribution by years.
The Handala group (MOIS-linked Iranian hacktivists) conducted destructive wiper operations against Israeli targets using commodity Russian malware for intelligence collection, followed by custom destructive tools.
F5UPDATER Campaign (2023):
F5UPDATER.exe — signed with "Skytec Global Ltd" certificate (SSL.com, 2023-12-17, subsequently revoked).Handala.exe runs first — deploys Rhadamanthys infostealer via Asgard Protector loader (AV enumeration, binary fragment reassembly via Naples.pif, process hollowing via WerFault.exe).Hatef.exe runs second — the actual wiper (ConfirmDeleteFiles).INCD Impersonation (April 2024): Handala impersonated Israel's National Cyber Directorate via incd[.]org[.]il, delivering encrypted ZIP → WSF → Asgard Protector → Rhadamanthys again.
| Campaign | Iranian Actor | Commodity Tool (Russian) | Certificate | Custom Tool |
|---|---|---|---|---|
| F5UPDATER (2023) | Handala | Rhadamanthys (Asgard Protector) | "Skytec Global Ltd" (purchased, revoked) | Hatef wiper |
| INCD impersonation (2024) | Handala | Rhadamanthys (Asgard Protector) | Non-reused CF domains | Wiper |
| Ctrl-Alt-Intel server (2026) | MuddyWater | Tsundere Bot / ChainShell (TAG-150) | "Amy Cherne" / "Donald Gay" | KeyC2, PersianC2 |
| CastleRAT MaaS (2025–2026) | Attributed to MuddyWater | CastleRAT, Stagecomp/Darkcomp (TAG-150) | "Amy Cherne" / "Donald Gay" | None identified |
The consistent pattern: Iranian actors purchase commodity Russian malware for collection and purchase code-signing certificates from criminal MSaaS vendors. Their custom tools (wipers, Farsi C2 frameworks) are separate and distinct. When vendors attribute the commodity tools to the Iranian actors as if they developed them, they are conflating consumption with ownership.
HIGH — The Seedworm attribution is incorrect as stated. Every IOC has been independently identified as commodity malware by other vendors, and the sole technical link (code-signing certificates) is a documented commodity service.
HIGH — zhivachkapro[.]com is ClixFlare infrastructure.
MODERATE — Seedworm may have used ClixFlare-delivered access as an entry point at specific targets, but the malware itself (CastleRAT, Tsundere Bot, Stagecomp/Darkcomp) is commodity MaaS available to any buyer.
All hashes and domains below have been attributed to Seedworm/MuddyWater by one or more vendors. We assess these are commodity MaaS artifacts, not APT-exclusive tooling.
| SHA-256 | Symantec | Talos | ThreatDown | Check Point | Rapid7 | CyberProof |
|---|---|---|---|---|---|---|
bd8203ab... | Dindoor | Dindoor | CastleRAT MSI | — | — | — |
2a00705c... | Dindoor | — | CastleRAT dropper | — | — | CastleRAT dropper |
2a09bbb3... | Dindoor | — | — | DinDoor/Tsundere | — | — |
077ab28d... | Fakeset | — | — | FakeSet/CastleLoader | — | — |
24857fe8... | Stagecomp | — | — | StageComp | ms_upd.exe | — |
a92d28f1... | Stagecomp | — | — | — | DIDS.exe | — |
3df9dcc4... | Darkcomp | — | — | — | WebView2.exe | — |
1319d474... | Darkcomp | — | — | — | Game.exe | — |
29b777e7... | — | "Seedworm Loader" | — | — | — | — |
500ee774... | — | — | — | — | — | CastleRAT MSI (Teams) |
| Indicator | Symantec | Talos | ThreatDown | Rapid7 | Red Canary | CyberProof |
|---|---|---|---|---|---|---|
serialmenot[.]com | ✓ | ✓ | ✓ (CastleRAT C2) | — | — | ✓ |
moonzonet[.]com | ✓ | ✓ | — | ✓ (Darkcomp C2) | ✓ (Darkcomp C2) | — |
uploadfiler[.]com | — | — | — | ✓ (config C2) | ✓ (Darkcomp C2) | — |
zhivachkapro[.]com | — | ✓ | ✓ (CastleRAT ClickFix) | — | — | — |
gitempire...backblazeb2[.]com | ✓ | ✓ | — | — | — | — |
elvenforest...backblazeb2[.]com | ✓ | ✓ | — | — | — | — |
uppdatefile[.]com | ✓ | ✓ | — | — | — | — |
| Field | "Donald Gay" | "Amy Cherne" |
|---|---|---|
| Issuer | Microsoft ID Verified CS AOC CA 02 | Microsoft ID Verified CS AOC CA 02 |
| Thumbprint | B674578D4BDB24CD58BF2DC884EAA658B7AA250C | 0902D7915A19975817EC1CCB0F2F6714AED19638 |
| Serial | 3300079A51C7063E66053D229B000000079A51 | 330007F1068F41BF0F662A03B500000007F106 |
| Status | Revoked (time-invalid) | Revoked (time-invalid) |
| Signs | Stagecomp, Darkcomp, Fakeset, Dindoor | Fakeset, Dindoor |
| Counter-evidence | Fox Tempest MSaaS sells equivalent certs for $5k–$9k[9] | Same |
Trojan.Dindoor (CastleRAT):
| SHA-256 | Notes |
|---|---|
0f9cf1cf8d641562053ce533aaa413754db88e60404cab6bbaa11f2b2491d542 | |
1d984d4b2b508b56a77c9a567fb7a50c858e672d56e8cf7677a1fca5c98c95d1 | |
2a00705cfd3c15cf8913e9eb4e23968efd06f1feceaef9987d26c5518887d043 | Also ThreatDown CastleRAT dropper[10] |
2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5 | Also Check Point DinDoor/Tsundere[3] |
42a5db2a020155b2adb77c00cbe6c6ad27c2285d8c6114679d9d34137e870b3f | |
7467f326677a4a2c8576e71a832e297e794ea00e9b67c4fcbe78b5aec697cec4 | |
7c30c16e7a311dc0cdb1cdfd9ea6e502f44c027328dbe7d960b9bcd85ccf5eef | |
b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0 | |
bd8203ab88983bc081545ff325f39e9c5cd5eb6a99d04ae2a6cf862535c9829a | Also ThreatDown CastleRAT MSI[10], Talos[2] |
c7cf1575336e78946f4fe4b0e7416b6ebe6813a1a040c54fb6ad82e72673478e |
Trojan.Fakeset (CastleLoader):
| SHA-256 | Notes |
|---|---|
077ab28d66abdafad9f5411e18d26e87fe43da1410ee8fe846bd721ab0cb52de | Also Check Point FakeSet/CastleLoader[3] |
15061036c702ad92b56b35e42cf5dc334597e7311e98d2fdd3815a69ac3b1d84 | |
2b7d8a519f44d3105e9fde2770c75efb933994c658855dca7d48c8b4897f81e6 | |
4aef998e3b3f6ca21c78ed71732c9d2bdcc8a4e0284f51d7462c79d446fbc7be | |
64263640a6fdeb2388bca2e9094a17065308cf8dcb0032454c0a71d9b78327eb | |
64cf334716f15da1db7981fad6c81a640d94aa1d65391ef879f4b7b6edf6e7f1 | |
74db1f653da6de134bdc526412a517a30b6856de9c3e5d0c742cb5fe9959ad0d | |
94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444 | |
a4bd1371fe644d7e6898045cc8e7b5e1562bdfd0e4871d46034e29a22dec6377 | |
a5d4d6be3bfe0cba23fe6b44984b5fc9c7c7e10030be96120bb30da0f2545d4c | |
ddceade244c636435f2444cd4c4d3dc161981f3af1f622c03442747ecef50888 |
Trojan.Stagecomp / Trojan.Darkcomp:
| SHA-256 | Type | Notes |
|---|---|---|
24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14 | Stagecomp | Also Rapid7[4] ms_upd.exe, Check Point[3] |
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0 | Stagecomp | Also Rapid7[4] DIDS.exe |
3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90 | Darkcomp | Also Rapid7[4] WebView2.exe |
1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6 | Darkcomp | Also Rapid7[4] Game.exe |
Symantec domains:
| Indicator | Type | Notes |
|---|---|---|
gitempire.s3.us-east-005.backblazeb2[.]com | Backblaze B2 | Fakeset staging (also in Talos[2]) |
elvenforest.s3.us-east-005.backblazeb2[.]com | Backblaze B2 | Fakeset staging (also in Talos[2]) |
uppdatefile[.]com | Domain | Also in Talos[2] |
serialmenot[.]com | Domain | CastleRAT C2 (also in Talos, ThreatDown, CyberProof) |
moonzonet[.]com | Domain | Also in Talos[2], Rapid7[4] |
| Indicator | Type | Notes |
|---|---|---|
hxxps://iuumfgrrnuhb[.]zhivachkapro[.]com/pobor | URL | ClixFlare C2, different endpoint from /cobor |
terymar[.]com | Domain | /install/Spf.ps1 — Node.js 18.17.0 + EtherHiding |
29b777e7c5470d557e34f3b7b76d2ee291c2dfe7fbaee72821b53eb50a4062c8 | SHA-256 | Spf.ps1 — Tsundere Bot installer |
| Indicator | Type | Notes |
|---|---|---|
dsennbuappec[.]zhivachkapro[.]com | URL | CastleRAT ClickFix C2 |
qzfbxajdtw[.]zhivachkapro[.]com/pobor | URL | CastleRAT dropper delivery |
serialmenot[.]com | Domain | CastleRAT JS loader C2 |
172[.]86.123.222 | IP | Python loader C2 |
23[.]94.145.120 | IP | CastleRAT C2 |
2a00705cfd3c15cf8913e9eb4e23968efd06f1feceaef9987d26c5518887d043 | SHA-256 | CastleRAT dropper (PS1) |
bd8203ab88983bc081545ff325f39e9c5cd5eb6a99d04ae2a6cf862535c9829a | SHA-256 | clickzpaqkvba.msi — also Symantec[1] |
a4787a42070994b7f1222025828faf9b153710bb730e58da710728e148282e28 | SHA-256 | CastleRAT PE payload |
VirtualSmokestGuy666 | Schtask | CastleRAT persistence |
CFBAT.jpg | File | Steganographic payload container |
clickzpaqkvba.msi | File | CastleRAT MSI installer |
| Indicator | Type | Notes |
|---|---|---|
24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14 | SHA-256 | ms_upd.exe (Stagecomp) |
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0 | SHA-256 | DIDS.exe (Stagecomp) |
1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6 | SHA-256 | Game.exe (Darkcomp) |
3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90 | SHA-256 | WebView2.exe (Darkcomp) |
c86ab27100f2a2939ac0d4a8af511f0a1a8116ba856100aae03bc2ad6cb0f1e0 | SHA-256 | visualwincomp.txt (encrypted C2 config) |
a47cd0dc12f0152d8f05b79e5c86bac9231f621db7b0e90a32f87b98b4e82f3a | SHA-256 | WebView2Loader.dll |
moonzonet[.]com | Domain | Darkcomp C2 |
uploadfiler[.]com | Domain | C2 from encrypted config |
adm-pulse[.]com | Domain | Quick Assist themed phishing |
172[.]86.126.208 | IP | C2 hosting Stagecomp |
116[.]203.208.186 | IP | Contacted by renamed pythonw.exe |
| Donald Gay cert | Thumbprint B674578D... | Same cert as Symantec/Check Point |
| Indicator | Type | Notes |
|---|---|---|
dntix[.]com | Domain | QuickAssist social engineering lure |
ms_upd.exe | File | Stagecomp — same as Rapid7[4], Symantec[1] |
moonzonet[.]com | Domain | Darkcomp C2 |
MessageBox.exe → Mozilla-fbbf0ab6.exe | File | Darkcomp RAT persistence path |
uploadfiler[.]com | Domain | Darkcomp C2 |
144[.]172.111.233 | IP | Reverse SSH tunnel endpoint |
asuedulimit | SSH user | Reverse tunnel authentication (-R 54321) |
| Indicator | Type | Notes |
|---|---|---|
seqhelpsitdevsupportops[.]onmicrosoft.com | M365 tenant | Teams social engineering ("Sarah Wilson") |
500ee77471669175b359bf57384291cab791200191d0e5a5bb190da53ccb30ee | SHA-256 | update_ms.msi — CastleRAT MSI |
dd3.filedwnl[.]top | Domain | Secondary payload server |
dd4.filedwnl[.]top | Domain | Secondary payload server |
140[.]82.18.48 | IP | C2 |
serialmenot[.]com | Domain | CastleRAT C2 |
Falcon_module63.vbs | File | CastleRAT component |
tango13.ps1 | File | PowerShell downloader |
The Seedworm/MuddyWater attribution of CastleRAT, Tsundere Bot, and ClixFlare infrastructure represents a systemic failure in threat intelligence methodology — not a failure of any single vendor, but the cumulative effect of an attribution cascade where each publication reinforced the last without independent verification of the foundational claim.
The sequence is clear: Symantec attributed commodity malware to an Iranian state unit based on a shared code-signing certificate and an uncitable prior attribution. Talos echoed it. Check Point, Rapid7, CyberProof, and JUMPSEC each inherited the attribution through IOC matching, adding their own incidents to the same pile without questioning the base layer. By July 2026, seven vendor publications had collectively transformed a Russian criminal MaaS platform into "Iranian state capability" — while five independent observers who encountered the same tooling earlier saw nothing but commodity cybercrime.
The irony is that JUMPSEC — whose analysis is the most technically rigorous — explicitly reached the correct conclusion: MuddyWater is a customer of TAG-150, not its developer.[6] Yet even this finding was framed as "MuddyWater's Russian MaaS Link" rather than what it actually demonstrates: that the TAG-150 ecosystem is a multi-tenant criminal service whose customer list tells you nothing about who operates it.
The practical consequences are significant. Defenders who ingest Seedworm IOC feeds now have commodity MaaS infrastructure mapped to an Iranian state actor, generating false positives whenever any TAG-150 customer — LeakNet ransomware, Chaos RaaS affiliates, random fake-installer campaigns — triggers the same indicators. The attribution has not improved anyone's security posture; it has degraded it.
The correct framing: zhivachkapro[.]com is ClixFlare — a commodity initial access broker. CastleRAT and Tsundere Bot are TAG-150 — a Russian criminal MaaS platform. The "Amy Cherne" and "Donald Gay" certificates are receipts from a signing service, not fingerprints of a state actor. MuddyWater may well be one of many customers who purchased access through these services — but the services themselves, and the infrastructure that delivers them, are not Iranian state operations.