Campaign record
MuddyWater deploying Level RMM
Level remote monitoring software installed by a fake Microsoft security update email
- Status as last assessed
- Dormant
- First seen
- 2024-11-13
- Last seen
- 2024-11-14
- Indicators
- 2
- Sources
- 1
- Targets
- Windows
- Fake security update notice
- Level RMM
- Phishing email
Original research
- Proofpoint2025-04-16Vendor researchFirst account
Around the World in 90 Days: State-Sponsored Actors Try ClickFix
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Over two days in November 2024 the Iranian group Proofpoint calls TA450, known elsewhere as MuddyWater and Mango Sandstorm, mailed staff at 39 or more organisations from an address on a look-alike Microsoft domain it had registered. The message posed as an urgent patch notice. Unusually for this technique there was no web lure at all: the instructions sat in the mail body, telling the reader to open PowerShell with administrator rights and paste in a supplied line. That line pulled down Level, a commercial remote monitoring and management product, which the operators then drove for espionage and data theft rather than deploying custom malware. Israel's national cyber directorate named the tool the next day. Proofpoint had watched the group lean on Atera, PDQ Connect, ScreenConnect and SimpleHelp before, though not Level. Targets clustered in the Gulf, weighted towards finance and government.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is PowerShell (T1059.001), which 19 of the 44 published campaigns in this corpus also record (43%).
Indicators
2 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
| Indicator | Type | Role | Assessment | First seen | Last seen | Report an error |
|---|---|---|---|---|---|---|
| domain, shown defanged for safety: microsoftonlines dot com | domain | Other | Attacker-controlled | 2024-11-13 | 2024-11-14 | Report an error in domain record 69f24130-552e-4b83-8b45-bbaa529246cd |
| email, shown defanged for safety: support at microsoftonlines dot com | Other | Attacker-controlled | 2024-11-13 | 2024-11-14 | Report an error in email record 04c9fd9c-bb69-41ea-8f07-c3d0869b878c |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “MuddyWater deploying Level RMM”, campaign ID 14797046, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/14797046/muddywater-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.