UDPgangster
UDPGangster is a custom backdoor used by the Iran-linked threat actor MuddyWater, also tracked as Boggy Serpens and assessed in the provided reporting as linked to Iran’s Ministry of Intelligence and Security (MOIS). It is described as a basic or lighter backdoor that communicates with its command-and-control infrastructure over the UDP protocol, including use of UDP port 1269, and has been characterized as a custom UDP C2 framework recovered from source code file udp_3.0.py with a SQLite backend for victim tracking. Reported C2 endpoints include 157.20.182.75:1269/UDP and 64.7.198.12:1269/UDP, and one delivery domain mentioned is reminders[.]trahum[.]org.
The malware has been delivered in phishing campaigns using malicious Microsoft Word documents and executable files disguised as PDFs or DOC files. In documented campaigns, victims were lured into enabling VBA macros, after which the macro decoded embedded data, wrote payload material to disk, and executed the UDPGangster payload. One reported lure used a ZIP file named seminer.zip containing a Word document named seminer.doc, and some phishing emails impersonated the Turkish Republic of Northern Cyprus Ministry of Foreign Affairs and referenced a fake seminar titled "Presidential Elections and Results." The malware has also been associated with broader MuddyWater phishing operations using hijacked legitimate email accounts and macro-enabled Office attachments.
Observed targeting in the provided content includes Microsoft Windows systems and entities in Turkey, Israel, and Azerbaijan, with additional reporting tying MuddyWater campaigns using UDPGangster to diplomatic, energy, maritime, government, aviation, financial, telecommunications, academia, engineering, local government, manufacturing, technology, transportation, and utilities-related targets in the Middle East and nearby regions. Unit 42 reporting in the content also states UDPGangster was used in a four-wave campaign against a UAE-based marine and energy company between August 2025 and February 2026.
Capabilities directly described in the content include persistence via Windows Registry modification and use of the victim persistence path %AppData%\RoamingLow\SystemProc.exe; system information gathering; command execution through cmd.exe; file transmission; exfiltration of data; updating the C2 server; and dropping additional payloads. Anti-analysis behavior reported for UDPGangster includes checks for debugging, sandboxing, virtualization, CPU, RAM, MAC address, workgroup, running processes, virtual machine artifacts, and debugger presence, with execution proceeding only if checks are satisfied. One report states the malware connected to 157.20.182[.]75 over UDP port 1269 after collecting host information.
The content also links UDPGangster to a shared MuddyWater development pipeline. Unit 42 reporting states that UDPGangster operations deployed a lighter UDP backdoor in parallel with the Phoenix lineage, and that both tracks shared an identical decryption key and the novaservice.exe file path, indicating common development. Additional reporting notes UDPGangster alongside other MuddyWater malware families including Phoenix, BugSleep, Nuso, RustyWater, GhostBackDoor, and LampoRAT/CHAR.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-54068 (CVSS score: 9.8) - A code injection vulnerability in Laravel Livewire that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. (Fixed in July 2025)
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Framework 1: UDPGangster -- UDP Port 1269 Source file: udp_3.0.py (1,310 lines of Python) This is the custom UDP C2 previously identified by FortiGuard Labs.
Techniques & procedures
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
2 techniques
Execution
Stealth
1 technique
Stealth
Command and Control
4 techniques
Command and Control
...and the UDPGangster Operations, deploying a lighter backdoor over UDP... Regular threat hunting for UDP-based beaconing...
“redundant command-and-control channels across HTTPS …” / “Cloudflare Workers, Firebase, OneDrive …” / “Firebase-hosted staging pages”
MITRE ATT&CK Mapping Technique ID Name Evidence T1071.003 Non-Application Layer Protocol UDPGangster (UDP 1269), ICMP tunneling
When that happens, a VBA macro executes silently in the background, drops a payload... Forensic analysis uncovered two parallel VBA builder tracks... delivering full backdoors including BugSleep and the newly identified Nuso HTTP backdoor, and the UDPGangster Operations, deploying a lighter backdoor over UDP.
IOCs tracked for this family
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used in MuddyWater's arsenal.
A lighter UDP-based backdoor used in operations linked to the same development pipeline as Phoenix Lineage.
Custom UDP-based command-and-control framework with victim tracking in SQLite, supporting beaconing, command execution, file upload/download, staging payloads, and persistence via %AppData%\RoamingLow\SystemProc.exe.
UDP-based MuddyWater backdoor used in campaigns including one targeting a financial institution in Egypt.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.