Huntress analysts uncovered a full intrusion timeline attributed to MuddyWater, an Iranian-linked APT, targeting an Israeli company. The attack chain began with RDP initial access, followed by reconnaissance commands (whoami, net, nltest), establishment of SSH reverse tunnels to 162.0.230[.]185, and deployment of malware via DLL side-loading — using the legitimate FMAPP.exe (Fortemedia Inc.) to load a malicious FMAPP.dll that communicated with C2 at 157.20.182[.]49. The detailed command timeline reveals attacker typos suggesting manual keyboard operation, deliberate process tree manipulation to appear legitimate, and C2 connectivity verification steps. IOCs including IP addresses, the SSH username, and file paths are provided.