MuddyWater — APT Profile
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, COBALT ULSTER, G0069, ATK51, Boggy Serpens, MUDDYCOAST, MUDDY ION
IntelFusions coverage (11)
- Stealthy spies hit Middle East governments by hiding in Telegram traffic 2026-07-20 · Nation-State
- State-backed hackers hide attacks inside AI tools and trusted cloud apps 2026-07-14 · Nation-State
- Iran-linked group targets Israeli firms with a stealthy new spy toolkit 2026-07-06 · Nation-State
- ToddyCat hackers steal corporate Gmail access with a stealthy new tool 2026-06-30 · Nation-State
- State-Sponsored Actors Weaponize Commercial AI: China-Linked Group Automates 80–90% of Attack Chain via Jailbroken Coding Assistant 2026-02-23 · AI Security
- Operation Olalampo: MuddyWater Deploys Rust CHAR Backdoor, GhostFetch/GhostBackDoor, and Telegram Bot C2 Against MENA Organizations 2026-02-20 · Nation-State
- DHCSpy Android Spyware: MuddyWater's VPN-Masquerading Surveillance Tool Active Since August 2022 Targets WhatsApp, Contacts, and Media 2026-02-16 · Nation-State
- MuddyWater Targets CFOs Globally with Firebase CAPTCHA Phishing, NetBird Abuse, and Hidden Admin Account Persistence 2026-02-16 · Nation-State
- MuddyWater Replaces Atera RMM with Custom MuddyRot C Implant: PDF-to-Egnyte Delivery, COM-Based Scheduled Task Persistence, and Raw TCP C2 2026-02-16 · Nation-State
- MuddyWater Deploys BugSleep Backdoor Against Israeli Municipalities, Airlines, and Media: Active Development with EDR Evasion via ProcessSignaturePolicy 2026-02-16 · Nation-State
- MuddyWater Targets Turkish and Pakistani Organizations with Canary Token Anti-Analysis, PDF Lures, and PowerShell Downloaders 2026-02-16 · Nation-State
Tools & malware
- ConnectWise Remote Access
- CrackMapExec Network Toolkit
- Empire Post-Exploitation Framework
- Koadic Post-Exploitation Framework
- LaZagne Credential Harvesting
- Mimikatz Credential Harvesting
- Mori Backdoor
- Out1 Exploitation Tool
- PowerSploit Post-Exploitation Framework
- POWERSTATS Backdoor
- PowGoop Backdoor
- RemoteUtilities Remote Access
- SHARPSTATS Backdoor
- Small Sieve Backdoor
- STARWHALE Backdoor
Vendor research
- A dive into MuddyWater APT targeting Middle-East Reaqta
- Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign Singh, S. et al.
- Check Point Research Check Point Research
- Group-IB Group-IB
- Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company Threat Hunter Team
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict FalconFeeds.io
- MuddyWater: Snakes by the riverbank ESET Research
- Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation Hunt.io
- How Microsoft names threat actors Microsoft
- Around the World in 90 Days: State-Sponsored Actors Try ClickFix Naumaan, S., et al
- MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign ClearSky
- Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign FireEye
- Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal ClearSky
- Iranian intel cyber suite of malware uses open source tools CYBERCOM
- Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks DHS
- Muddying the Water: Targeted Attacks in the Middle East Unit 42
- Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables Talos
- Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies Anomali
- Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign Proofpoint
- Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East Trend Micro
- Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms Symantec
- A dive into MuddyWater APT targeting Middle-East Reaqta MuddyWater