Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareUsed by 1 actorExploits 1 CVE

UDPgangster

UDPGangster is a custom backdoor used by the Iran-linked threat actor MuddyWater, also tracked as Boggy Serpens and assessed in the provided reporting as linked to Iran’s Ministry of Intelligence and Security (MOIS). It is described as a basic or lighter backdoor that communicates with its command-and-control infrastructure over the UDP protocol, including use of UDP port 1269, and has been characterized as a custom UDP C2 framework recovered from source code file udp_3.0.py with a SQLite backend for victim tracking. Reported C2 endpoints include 157.20.182.75:1269/UDP and 64.7.198.12:1269/UDP, and one delivery domain mentioned is reminders[.]trahum[.]org.

The malware has been delivered in phishing campaigns using malicious Microsoft Word documents and executable files disguised as PDFs or DOC files. In documented campaigns, victims were lured into enabling VBA macros, after which the macro decoded embedded data, wrote payload material to disk, and executed the UDPGangster payload. One reported lure used a ZIP file named seminer.zip containing a Word document named seminer.doc, and some phishing emails impersonated the Turkish Republic of Northern Cyprus Ministry of Foreign Affairs and referenced a fake seminar titled "Presidential Elections and Results." The malware has also been associated with broader MuddyWater phishing operations using hijacked legitimate email accounts and macro-enabled Office attachments.

Observed targeting in the provided content includes Microsoft Windows systems and entities in Turkey, Israel, and Azerbaijan, with additional reporting tying MuddyWater campaigns using UDPGangster to diplomatic, energy, maritime, government, aviation, financial, telecommunications, academia, engineering, local government, manufacturing, technology, transportation, and utilities-related targets in the Middle East and nearby regions. Unit 42 reporting in the content also states UDPGangster was used in a four-wave campaign against a UAE-based marine and energy company between August 2025 and February 2026.

Capabilities directly described in the content include persistence via Windows Registry modification and use of the victim persistence path %AppData%\RoamingLow\SystemProc.exe; system information gathering; command execution through cmd.exe; file transmission; exfiltration of data; updating the C2 server; and dropping additional payloads. Anti-analysis behavior reported for UDPGangster includes checks for debugging, sandboxing, virtualization, CPU, RAM, MAC address, workgroup, running processes, virtual machine artifacts, and debugger presence, with execution proceeding only if checks are satisfied. One report states the malware connected to 157.20.182[.]75 over UDP port 1269 after collecting host information.

The content also links UDPGangster to a shared MuddyWater development pipeline. Unit 42 reporting states that UDPGangster operations deployed a lighter UDP backdoor in parallel with the Phoenix lineage, and that both tracks shared an identical decryption key and the novaservice.exe file path, indicating common development. Additional reporting notes UDPGangster alongside other MuddyWater malware families including Phoenix, BugSleep, Nuso, RustyWater, GhostBackDoor, and LampoRAT/CHAR.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-54068Unauthenticated RCE in Laravel Livewire v3 hydrationExploited in the wild

CVE-2025-54068 (CVSS score: 9.8) - A code injection vulnerability in Laravel Livewire that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. (Fixed in July 2025)

via the hacker newsthehackernews.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
MuddyWater

Framework 1: UDPGangster -- UDP Port 1269 Source file: udp_3.0.py (1,310 lines of Python) This is the custom UDP C2 previously identified by FortiGuard Labs.

via breakglass intelintel.breakglass.tech
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1190Exploit Public-Facing ApplicationEvidence1

MITRE ATT&CK Mapping Technique ID Name Evidence T1190 Exploit Public-Facing Application CVE-2024-55591 (FortiGate), CVE-2026-1281 (Ivanti), CVE-2025-5777 (Citrix)

T1566.001Spearphishing AttachmentEvidence2

MITRE ATT&CK Mapping Technique ID Name Evidence T1566.001 Spearphishing Attachment ArenaReport lure site, UDPGangster delivery documents

Execution

2 techniques
T1059.003Windows Command ShellEvidence1

MITRE ATT&CK Mapping Technique ID Name Evidence T1059.003 Windows Command Shell C2 command execution via +cmd

T1059.006PythonEvidence1

MITRE ATT&CK Mapping Technique ID Name Evidence T1059.006 Python All C2 frameworks written in Python

Stealth

1 technique
T1140Deobfuscate/Decode Files or InformationEvidence1

“…employ multiple obfuscation techniques (T1140) …” / “modified UPX packing … encrypts its configuration using AES-256-CBC …”

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence2

...and the UDPGangster Operations, deploying a lighter backdoor over UDP... Regular threat hunting for UDP-based beaconing...

T1071.001Web ProtocolsEvidence1

“redundant command-and-control channels across HTTPS …” / “Cloudflare Workers, Firebase, OneDrive …” / “Firebase-hosted staging pages”

T1071.003Mail ProtocolsEvidence1

MITRE ATT&CK Mapping Technique ID Name Evidence T1071.003 Non-Application Layer Protocol UDPGangster (UDP 1269), ICMP tunneling

T1105Ingress Tool TransferEvidence1

When that happens, a VBA macro executes silently in the background, drops a payload... Forensic analysis uncovered two parallel VBA builder tracks... delivering full backdoors including BugSleep and the newly identified Nuso HTTP backdoor, and the UDPGangster Operations, deploying a lighter backdoor over UDP.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence2

MITRE ATT&CK Mapping Technique ID Name Evidence T1041 Exfiltration Over C2 Channel File download via +download command

INDICATORS OF COMPROMISE

IOCs tracked for this family

15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
11 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app2 months ago
ip.v4●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching15

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.