A recently discovered campaign shows that the cyber-espionage group MuddyWater has updated tactics, techniques and procedures (TTPs) to evade detection, Talos' security researchers report. MuddyWater was first detailed in 2017 and has been highly active throughout 2018. The cyber-spies have been focused mainly on governmental and telco targets in the Middle East (Iraq, Saudi Arabia, Bahrain, Jordan, Turkey and Lebanon) and nearby regions (Azerbaijan, Pakistan and Afghanistan). The recently observed campaign, which Talos calls BlackWater , aims to install a PowerShell-based backdoor onto the victim's machine, for remote access. Analyzed samples show that, while the actor made changes to bypass security controls, the underlying code was unchanged. Observed modifications include the use of an obfuscated VBA script to establish persistence as a registry ke...