From 10770e1329623deb1b32c2aa7d7048f50a2f5694 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Mon, 16 Feb 2026 04:58:57 -0500 Subject: [PATCH] Update README.md --- Iranian APT/Static Kitten/README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/Iranian APT/Static Kitten/README.md b/Iranian APT/Static Kitten/README.md index 08c7bdd..8d65501 100644 --- a/Iranian APT/Static Kitten/README.md +++ b/Iranian APT/Static Kitten/README.md @@ -1,2 +1,3 @@ # Static Kitten APT Adversary Simulation +This is a simulation of attack by (Static Kitten) APT group targeting multiple sectors across the Middle East, including diplomatic, maritime, financial, and telecom entities. The campaign uses icon spoofing and malicious Word documents to deliver "RustyWater," a Rust-based implant representing a significant upgrade to their traditional toolkit, the attack campaign was active early as January 2026. The attackers has relied on PowerShell and VBS loaders for initial access and post-compromise operations. The introduction of Rust-based implants represents a notable tooling evolution toward more structured, modular, and low noise RAT capabilities. I relied on cloudsek to figure out the details to make this Simulation: https://www.cloudsek.com/blog/reborn-in-rust-muddywater-evolves-tooling-with-rustywater-implant