bugsleep
Aliases: MuddyRot
- First seen
- 2020-05-15 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:50:57
Targeted industries: government-and-public-sector financial-services energy-and-utilities defense-and-aerospace
Targeted regions: country_code:us country_code:de country_code:ru
Context
Bugsleep, also known as MuddyRot, is a stealthy remote access tool (RAT) primarily used by threat actors for cyber espionage. It allows attackers to maintain persistent access to compromised systems in targeted regions such as the US, Germany, and Russia, focusing on government and critical infrastructure sectors.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Bugsleep (report)
- raw-data.gitlab.io — Bugsleep Netprotocol (report)
- Cisco Talos — Writing A Bugsleep C2 Server (report)
- blog.sekoia.io — Muddywater Replaces Atera By Custom Muddyrot Implant In A Recent Campaign (report)
- nikhilh-20.github.io — Inject Bugsleep (report)
- research.checkpoint.com — New Bugsleep Backdoor Deployed In Recent Muddywater Campaigns (report)