Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Symantec reported that the Iran-linked group known as Seedworm, or MuddyWater, targeted telecommunications organizations in Egypt, Sudan and Tanzania during November 2023. The victims were not named. Investigators documented espionage-oriented access and a mix of PowerShell, legitimate remote-access software, proxy tools and custom malware, but did not establish what subscriber or network data was stolen or report service outages.

What Symantec reported

Symantec’s Threat Hunter Team said most of the activity it observed centered on one telecommunications organization. It also described activity involving two other organizations, one of which was a telecommunications and media company. None of the victims was publicly identified.

The Council on Foreign Relations’ incident tracker records the same three countries and sector and classifies the event as espionage. That classification reflects the reported targeting and access behavior; it is not evidence of a confirmed data-theft total, customer impact or operational disruption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Symantec said one organization appeared to have been infiltrated earlier in 2023. That earlier intrusion had not been definitively attributed at the time. Researchers assessed that the November activity provided evidence it was conducted by the same attackers. This is an analytic assessment of the likely timeline, not a publicly proven record of every stage of the intrusion.

#1 Best Overall
TP-Link 8 Port Gigabit Ethernet Network Switch - Ethernet Splitter | Plug & Play | Fanless | Sturdy Metal w/ Shielded Ports | Traffic Optimization | Unmanaged | Lifetime Protection (TL-SG108)
  • 8 GIGABIT PORTS: Features 8 RJ45 ports supporting 10/100/1000 Mbps speeds, providing high-speed wired network connectivity for computers, printers, gaming consoles, and other Ethernet-enabled devices
  • PLUG AND PLAY SETUP: No configuration required; simply connect the switch to your network devices and it is ready to use immediately, making network expansion quick and hassle-free
  • FANLESS QUIET DESIGN: The fanless design ensures silent operation, making this switch suitable for noise-sensitive environments such as home offices, bedrooms, or conference rooms
  • STURDY METAL CONSTRUCTION: Built with a durable metal housing and shielded ports that provide reliable performance, better heat dissipation, and protection against electromagnetic interference
  • TRAFFIC OPTIMIZATION: Supports IEEE 802.3x flow control and advanced traffic optimization technology to reduce data bottlenecks and ensure smooth, efficient data transfer across your network

What is Seedworm?

Seedworm is an alias associated with MuddyWater, a cyberespionage group that MITRE ATT&CK assesses as a subordinate element within Iran’s Ministry of Intelligence and Security (MOIS). Public reporting also uses the names MuddyWater and Seedworm for the same group.

MITRE records MuddyWater activity since at least 2017 against telecommunications, government, finance, defense, oil and gas and other sectors across the Middle East, Asia, Africa, Europe and North America. Symantec describes the group as most strongly associated with the Middle East, making the African telecommunications activity a notable geographic extension. “Affiliated with MOIS” is an open-source assessment, not a public admission by Iran or the unnamed victims.

Rank #2
Sale
TP-Link TL-SG105, 5 Port Gigabit Unmanaged Ethernet Switch, Network Hub, Ethernet Splitter, Plug & Play, Fanless Metal Design, Shielded Ports, Traffic Optimization
  • 𝗢𝗻𝗲 𝗦𝘄𝗶𝘁𝗰𝗵 𝗠𝗮𝗱𝗲 𝘁𝗼 𝗘𝘅𝗽𝗮𝗻𝗱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸: 5× 10/100/1000Mbps RJ45 Ports supporting Auto Negotiation and Auto MDI/MDIX.
  • 𝗚𝗶𝗴𝗮𝗯𝗶𝘁 𝘁𝗵𝗮𝘁 𝗦𝗮𝘃𝗲𝘀 𝗘𝗻𝗲𝗿𝗴𝘆: Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money.
  • 𝗥𝗲𝗹𝗶𝗮𝗯𝗹𝗲 𝗮𝗻𝗱 𝗤𝘂𝗶𝗲𝘁: IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation.
  • 𝗣𝗹𝘂𝗴 𝗮𝗻𝗱 𝗣𝗹𝗮𝘆: Easy setup with no software installation or configuration needed.
  • 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗙𝗲𝗮𝘁𝘂𝗿𝗲𝘀: Prioritize your traffic and guarantee high quality of video or voice data transmission with Port-based 802.1p/DSCP QoS and IGMP Snooping.

Which African countries were targeted?

Country Sector described by investigators What is publicly established
Egypt Telecommunications Targeted in the November 2023 activity reported by Symantec; victim not named.
Sudan Telecommunications Targeted in the November 2023 activity reported by Symantec; victim not named.
Tanzania Telecommunications Targeted in the November 2023 activity reported by Symantec; victim not named.

The country list describes the scope of this report, not the number of operators affected or a prevalence rate. Public accounts do not identify a particular mobile carrier, internet service provider, subscriber population or government response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the attackers operated

The campaign illustrates a “living off the land” approach: attackers combined their own tools with PowerShell, scheduled tasks and legitimate administration software that can look normal in an enterprise environment. Dark Reading’s contemporaneous account described this blend as a way to reduce conspicuous activity and evade detection.

Rank #3
Sale
NETGEAR 5-Port Gigabit Ethernet Unmanaged Network Switch (GS305)
  • GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
  • PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
  • FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
  • SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
  • REGIONAL COMPATIBILITY: Made for use in U.S. & CA only

MuddyC2Go and PowerShell

Symantec observed a MuddyC2Go PowerShell launcher. Its embedded PowerShell can contact command-and-control infrastructure and execute code returned by that infrastructure. The launcher can also remove the need for an operator to start individual scripts manually. Deep Instinct had previously documented MuddyC2Go in Middle Eastern attacks and said the framework might have been used by Seedworm since 2020; Symantec relayed that earlier assessment rather than presenting it as a newly proven date of origin.

Remote-access and proxy tools

The report lists SimpleHelp, AnyDesk, Venom Proxy and Revsocks among the tools seen in the activity. Remote-access products can provide interactive control, while proxy and reverse-socket tools can route traffic through compromised systems or conceal the path to command-and-control servers. The presence of a tool in the campaign does not mean it was deployed against every organization.

Rank #4
Sale
NETGEAR 5-Port Gigabit Ethernet Unmanaged Network Switch (GS105NA)
  • GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
  • PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
  • FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
  • SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
  • REGIONAL COMPATIBILITY: Made for use in U.S. & CA only

Persistence, execution and credential access

Symantec also recorded Windows scheduled tasks, Impacket WMIExec-like commands and use of the legitimate Java executable jabswitch.exe in a DLL-sideloading context. A custom keylogger was among the reported components. These observations show the kinds of execution, persistence and collection capabilities investigators encountered; they do not by themselves prove that keystrokes, credentials or network data were successfully exfiltrated.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the evidence does—and does not—show

  • Supported: targeting of telecommunications organizations in Egypt, Sudan and Tanzania during November 2023; use of the tools and techniques listed by Symantec; and an espionage framing in the incident tracker.
  • Not established publicly: the identities of the operators, the volume or type of stolen data, affected subscriber numbers, compromise of core network infrastructure, service outages, ransom demands or a confirmed government response.
  • Attribution caveat: Seedworm/MuddyWater and the MOIS relationship are public intelligence assessments. Symantec’s account is a vendor investigation, not a victim or government disclosure.

A separate Council on Foreign Relations entry describes MuddyWater activity beginning in February 2024 against suspected telecommunications firms and government agencies in Israel, Turkey and Africa. That later case is separate context and does not show that the same African organizations were affected.

Best Value
Sale
TP-Link LS1005G, Litewave 5 Port Gigabit Ethernet Unmanaged Switch
  • 【One Switch Made to Expand Network】Features 5 RJ45 ports with 10/100/1000Mbps speeds, supporting Auto-Negotiation and Auto MDI/MDIX for hassle-free setup. Ideal for expanding your network, with 1 uplink (input) port and 4 output ports to split your Ethernet connection to multiple devices.
  • 【Gigabit that Saves Energy】Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money
  • 【Reliable and Quiet】IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation
  • 【Plug and Play】Easy setup with no software installation or configuration needed
  • 【Ethernet Splitter】Connect to your router or modem for additional wired connections (laptop, gaming console, printer, etc)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How telecom operators can look for similar activity

The reported techniques suggest practical investigation priorities, but the campaign report is not a test of any specific security product and does not prove that a particular control would have prevented compromise.

  1. Audit PowerShell: enable detailed script-block and module logging, record parent-child process relationships and investigate encoded or remotely retrieved commands, especially from unusual service accounts.
  2. Inventory remote-access software: locate SimpleHelp, AnyDesk and other remote-support clients across endpoints; verify ownership, installation time, signer, account used and approved support cases. Remove or restrict unapproved instances.
  3. Monitor proxy and reverse-tunnel behavior: alert on Venom Proxy, Revsocks-like binaries, unexpected listening ports, outbound connections to rare destinations and traffic that bypasses the organization’s normal egress path.
  4. Review scheduled tasks and WMI: baseline task creation and changes, correlate them with interactive logons and inspect WMIExec-like remote process launches across server and workstation segments.
  5. Check DLL sideloading: investigate unusual launches of trusted binaries such as jabswitch.exe when the executable loads a DLL from a nonstandard or user-writable directory.
  6. Protect sensitive administration paths: separate management networks, require multifactor authentication for remote access, limit scripting privileges and preserve endpoint and network telemetry long enough to reconstruct activity across segments.
  7. Hunt for keylogging indicators: examine newly created services, unsigned input-monitoring modules, suspicious persistence and outbound collection from systems handling operator credentials or network-management sessions.

Why this matters to African telecoms and ISPs

Telecommunications environments combine high-value administrative access, extensive identity data and complex mixtures of legacy and modern systems. A malicious PowerShell script or remote-support client may be difficult to distinguish from routine maintenance unless operators maintain software inventories, centralized logs and clear approval records. The November 2023 reporting therefore matters primarily as a warning about stealthy access and investigation gaps—not as evidence that a named carrier suffered a publicly confirmed outage or mass customer breach.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.