Skip to content

Phoenix

Phoenix is a custom Windows backdoor associated primarily with the Iranian state-aligned threat actor MuddyWater, also tracked as Seedworm, TA450, Mango Sandstorm, and Static Kitten.

Profile source: Mallory opens in a new tab

Phoenix

Family profile

Phoenix is a custom Windows backdoor associated primarily with the Iranian state-aligned threat actor MuddyWater, also tracked as Seedworm, TA450, Mango Sandstorm, and Static Kitten. It has been used in espionage operations to establish persistent remote access on victim systems, support intelligence collection, and maintain long-term footholds in targeted environments. Reporting places its operational use from at least 2025, including campaigns against government entities, diplomatic organizations, international organizations, and energy-sector targets across the Middle East, North Africa, and parts of Africa.

Phoenix has been delivered through spear-phishing campaigns using malicious Microsoft Word documents with embedded VBA macros, as well as through executable payloads disguised as document files. In observed operations, macro-enabled documents deployed Phoenix directly or via intermediary components such as loaders. Campaigns have included use of compromised mailboxes and tailored lures, indicating deliberate targeting and pre-attack reconnaissance.

Functionally, Phoenix is a remote-access backdoor that gathers host information and enables attacker command execution and file operations. Documented capabilities include system-information collection, remote shell access, file upload and download, configurable beacon or sleep behavior, and persistence on infected Windows hosts. Later variants, including a reported version 4, introduced persistence changes and were deployed alongside additional tooling such as custom credential-stealing components and remote management software, reflecting MuddyWater’s broader shift toward bespoke implants combined with dual-use administration tools.

Phoenix has been described as part of MuddyWater’s evolving malware ecosystem alongside implants and loaders such as BugSleep, StealthCache, Fooder, RustyWater, CHAR, and UDPGangster. It has been used to provide strategic and persistent access for espionage, particularly against ministries, embassies, consulates, foreign-policy targets, and critical-sector organizations. High-confidence reporting supports classifying Phoenix as a backdoor used for long-term access, post-compromise control, persistence, and intelligence collection on Windows systems.

Capabilities

  • Credential Theft
  • Persistence
  • Post Exploitation

Reported operators

Threat actors

2 named in public reporting
MuddyWater

MuddyWater ... pour diffuser des malwares comme « Phoenix, FakeUpdate, StealthCache et Chromium_Stealer ».

Turla

“It also started using a new framework that we call Phoenix...”

MITRE ATT&CK

Phoenix in ATT&CK

17 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.