bugsleep

Aliases: MuddyRot

First seen
2020-05-15 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 14:50:57

Targeted industries: government-and-public-sector financial-services energy-and-utilities defense-and-aerospace

Targeted regions: country_code:us country_code:de country_code:ru

Context

Bugsleep, also known as MuddyRot, is a stealthy remote access tool (RAT) primarily used by threat actors for cyber espionage. It allows attackers to maintain persistent access to compromised systems in targeted regions such as the US, Germany, and Russia, focusing on government and critical infrastructure sectors.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Bugsleep (report)
  • raw-data.gitlab.io — Bugsleep Netprotocol (report)
  • Cisco Talos — Writing A Bugsleep C2 Server (report)
  • blog.sekoia.io — Muddywater Replaces Atera By Custom Muddyrot Implant In A Recent Campaign (report)
  • nikhilh-20.github.io — Inject Bugsleep (report)
  • research.checkpoint.com — New Bugsleep Backdoor Deployed In Recent Muddywater Campaigns (report)

External references