MuddyWater — APT Profile
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.Also tracked as
Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450
Tools & malware
- ConnectWise Remote Access
- CrackMapExec Network Toolkit
- Empire Post-Exploitation Framework
- Koadic Post-Exploitation Framework
- LaZagne Credential Harvesting
- Mimikatz Credential Harvesting
- Mori Backdoor
- Out1 Exploitation Tool
- PowerSploit Post-Exploitation Framework
- POWERSTATS Backdoor
- PowGoop Backdoor
- RemoteUtilities Remote Access
- SHARPSTATS Backdoor
- Small Sieve Backdoor
- STARWHALE Backdoor
Vendor research
- Check Point Research Check Point Research
- Group-IB Group-IB
- The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict FalconFeeds.io
- Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation Hunt.io
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- Around the World in 90 Days: State-Sponsored Actors Try ClickFix Naumaan, S., et al
- Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company Threat Hunter Team
- How Microsoft names threat actors Microsoft
- MuddyWater: Snakes by the riverbank ESET Research
- A dive into MuddyWater APT targeting Middle-East Reaqta MuddyWater
- MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign ClearSky
- Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms Symantec
- Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign FireEye
- Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal ClearSky
- Iranian intel cyber suite of malware uses open source tools CYBERCOM
- Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks DHS
- Muddying the Water: Targeted Attacks in the Middle East Unit 42
- Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables Talos
- Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies Anomali
- Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign Proofpoint
- Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East Trend Micro