MuddyWater Targets 100+ Gov Entities in MEA with Phoenix BackdoorThe Iranian threat group is using a compromised mailbox accessed through NordVPN to send phishing emails that prompt recipients to enable macros. October 22, 2025