Skip to content

Campaign record

MuddyWater deploying Level RMM

Level remote monitoring software installed by a fake Microsoft security update email

Status as last assessed
Dormant
First seen
2024-11-13
Last seen
2024-11-14
Indicators
2
Sources
1
Targets
Windows
  • Fake security update notice
  • Level RMM
  • Phishing email

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Over two days in November 2024 the Iranian group Proofpoint calls TA450, known elsewhere as MuddyWater and Mango Sandstorm, mailed staff at 39 or more organisations from an address on a look-alike Microsoft domain it had registered. The message posed as an urgent patch notice. Unusually for this technique there was no web lure at all: the instructions sat in the mail body, telling the reader to open PowerShell with administrator rights and paste in a supplied line. That line pulled down Level, a commercial remote monitoring and management product, which the operators then drove for espionage and data theft rather than deploying custom malware. Israel's national cyber directorate named the tool the next day. Proofpoint had watched the group lean on Atera, PDQ Connect, ScreenConnect and SimpleHelp before, though not Level. Targets clustered in the Gulf, weighted towards finance and government.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is PowerShell (T1059.001), which 19 of the 44 published campaigns in this corpus also record (43%).

Indicators

2 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenReport an error
domain, shown defanged for safety: microsoftonlines dot comdomainOtherAttacker-controlled2024-11-132024-11-14Report an error in domain record 69f24130-552e-4b83-8b45-bbaa529246cd
email, shown defanged for safety: support at microsoftonlines dot comemailOtherAttacker-controlled2024-11-132024-11-14Report an error in email record 04c9fd9c-bb69-41ea-8f07-c3d0869b878c

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “MuddyWater deploying Level RMM”, campaign ID 14797046, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/14797046/muddywater-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.