◇ SIGN IN
← all actors
apt

MuddyWater

activehigh confidence
APT / State-sponsored
Earth VetalaMERCURYStatic KittenSeedwormTEMP.ZagrosMango SandstormTA450MuddyKrill
Attribution
Iran — Ministry of Intelligence and Security (MOIS)
Origin
Iran
First seen
2017
Last active
2026
Motivation
Espionage
Confidence
high
MENA targeting
UAE, Saudi Arabia, Israel, Turkey, Iraq, Jordan, Egypt
Sectors
Telecom, local government, finance, defense, oil & gas, energy, marine services
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting UAE, Saudi Arabia, Israel (Telecom, local government, finance sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

MuddyWater is a prolific Iranian MOIS-subordinate cyber-espionage group that has targeted government, telecom, defense, and energy organizations across the Middle East since 2017, with heavy focus on Gulf states and Israel.

History

MuddyWater first surfaced publicly in 2017 and was formally attributed by U.S. Cyber Command in January 2022 as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS). The group is assessed to function as one of Iran's most active regional espionage arms, blending intelligence collection with occasional access-brokering for other Iranian clusters.

Across its lifetime MuddyWater has favored living-off-the-land tradecraft: malicious documents with macro or lure content, PowerShell-based footholds, and heavy abuse of legitimate remote-management tools (Atera, ScreenConnect, Syncro, RemoteUtilities) for command-and-control and persistence. The group also runs custom implants and has repeatedly refreshed its C2 infrastructure, showing a preference for NameCheap-registered domains and specific hosting providers.

MENA targeting is central to MuddyWater's mission. Reporting consistently places victims in the UAE, Saudi Arabia, Israel, Turkey, Iraq, Jordan, and Egypt, spanning telecommunications, local government, finance, defense, and oil-and-gas sectors. CISA's AA22-055A advisory (February 2022) documented its Middle East and broader campaigns in detail.

The group remains highly active into 2025–2026. MITRE ATT&CK notes MuddyWater reusing domains dating to October 2025 and, in late 2025 and early 2026, adopting commercial satellite internet (Starlink) for C2 — an assessed attempt to complicate infrastructure tracking and network-based detection. ESET (December 2025) and Symantec/Carbon Black (March 2026, tracked as Seedworm) reported continued regional operations, and researchers have documented operational overlaps with the HEXANE/Lyceum cluster where MuddyWater likely acts as an initial-access broker.

Notable campaigns

2019
PowGoop / regional espionage
Broad phishing-driven campaigns against Middle Eastern government and telecom targets using PowerShell downloaders.
2022
CISA AA22-055A operations
Joint U.S.-UK advisory detailing MuddyWater's MOIS-directed intrusions across government and private sectors.
2025
MuddyKrill / IAB activity
MuddyWater assessed acting as initial-access broker, deploying remote-desktop tools and a custom Mimikatz loader against Israeli manufacturing.
2026
Starlink C2 operations
Adoption of commercial satellite internet for command-and-control to evade infrastructure-based tracking.

Observed ATT&CK techniques · 68

TechniqueNameTacticObserved use
T1113Screen CapturecollectionMuddyWater has used malware that can capture screenshots of the victim's machine.
T1560.001Archive Collected Data: Archive via UtilitycollectionMuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data.
T1074.001Data Staged: Local Data StagingcollectionMuddyWater has stored a decoy PDF file within a victim's %temp% folder.
T1573.001Encrypted Channel: Symmetric Cryptographycommand and controlMuddyWater has used AES to encrypt C2 responses.
T1090Proxycommand and controlMuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France.
T1571Non-Standard Portcommand and controlMuddyWater has used ports 8043 and 8848 for botnet C2 communication.
T1071.001Application Layer Protocol: Web Protocolscommand and controlMuddyWater has used HTTP for C2 communications.
T1132.001Data Encoding: Standard Encodingcommand and controlMuddyWater has used tools to encode C2 communications including Base64 encoding.
T1105Ingress Tool Transfercommand and controlMuddyWater has used malware that can upload additional files to the victim's machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim's machine.
T1102.002Web Service: Bidirectional Communicationcommand and controlMuddyWater has used web services including OneHub to distribute remote access tools.
T1104Multi-Stage Channelscommand and controlMuddyWater has used one C2 to obtain enumeration scripts and monitor web logs, but a different C2 to send data back.
T1090.002Proxy: External Proxycommand and controlMuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT).
T1219.002Remote Access Software: Remote Desktop Softwarecommand and controlMuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions.
T1003.004OS Credential Dumping: LSA Secretscredential accessMuddyWater has performed credential dumping with LaZagne.
T1552.001Unsecured Credentials: Credentials In Filescredential accessMuddyWater has run a tool that steals passwords saved in victim email.
T1555Credentials from Password Storescredential accessMuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email.
T1555.003Credentials from Password Stores: Credentials from Web Browserscredential accessMuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.
T1003.001OS Credential Dumping: LSASS Memorycredential accessMuddyWater has performed credential dumping with Mimikatz and procdump64.exe.
T1003.005OS Credential Dumping: Cached Domain Credentialscredential accessMuddyWater has performed credential dumping with LaZagne.
T1685Disable or Modify Toolsdefense impairmentMuddyWater can disable the system's local proxy settings.
T1057Process DiscoverydiscoveryMuddyWater has used malware to obtain a list of running processes on the system.
T1518Software DiscoverydiscoveryMuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine.
T1087.002Account Discovery: Domain AccountdiscoveryMuddyWater has used cmd.exe net user /domain to enumerate domain users.
T1083File and Directory DiscoverydiscoveryMuddyWater has used malware that checked if the ProgramData folder had folders or files with keywords 'Kasper,' 'Panda,' or 'ESET.'
T1082System Information DiscoverydiscoveryMuddyWater has used malware that can collect the victim's OS version and machine name.
T1033System Owner/User DiscoverydiscoveryMuddyWater has used malware that can collect the victim's username.
T1016System Network Configuration DiscoverydiscoveryMuddyWater has used malware to collect the victim's IP address and domain name.
T1518.001Software Discovery: Security Software DiscoverydiscoveryMuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers.
T1049System Network Connections DiscoverydiscoveryMuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine.
T1047Windows Management InstrumentationexecutionMuddyWater has used malware that leveraged WMI for execution and querying host information.
T1059.007Command and Scripting Interpreter: JavaScriptexecutionMuddyWater has used JavaScript files to execute its POWERSTATS payload.
T1059.006Command and Scripting Interpreter: PythonexecutionMuddyWater has developed tools in Python including Out1.
T1204.002User Execution: Malicious FileexecutionMuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro.
T1204.004User Execution: Malicious Copy and PasteexecutionMuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code.
T1203Exploitation for Client ExecutionexecutionMuddyWater has exploited the Office vulnerability CVE-2017-0199 for execution.
T1204.001User Execution: Malicious LinkexecutionMuddyWater has distributed URLs in phishing e-mails that link to lure documents.
T1559.002Inter-Process Communication: Dynamic Data ExchangeexecutionMuddyWater has used malware that can execute PowerShell scripts via DDE.
T1559.001Inter-Process Communication: Component Object ModelexecutionMuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.
T1059.005Command and Scripting Interpreter: Visual BasicexecutionMuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.
T1059.003Command and Scripting Interpreter: Windows Command ShellexecutionMuddyWater has used a custom tool for creating reverse shells.
T1059.001Command and Scripting Interpreter: PowerShellexecutionMuddyWater has used PowerShell for execution.
T1053.005Scheduled Task/Job: Scheduled Taskexecution, persistence, privilege escalationMuddyWater has used scheduled tasks to establish persistence.
T1574.001Hijack Execution Flow: DLLexecution, stealthMuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware.
T1041Exfiltration Over C2 ChannelexfiltrationMuddyWater has used C2 infrastructure to receive exfiltrated data.
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud StorageexfiltrationMuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone.
T1566.002Phishing: Spearphishing Linkinitial accessMuddyWater has sent targeted spearphishing e-mails with malicious links.
T1566Phishinginitial accessMuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com.
T1566.001Phishing: Spearphishing Attachmentinitial accessMuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload.
T1190Exploit Public-Facing Applicationinitial accessMuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688).
T1534Internal Spearphishinglateral movementMuddyWater has used compromised mailboxes within target organizations to send spearphishing emails.
T1210Exploitation of Remote Serviceslateral movementMuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472).
T1137.001Office Application Startup: Office Template MacrospersistenceMuddyWater has used a Word Template, Normal.dotm, for persistence.
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folderpersistence, privilege escalationMuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.
T1548.002Abuse Elevation Control Mechanism: Bypass User Account Controlprivilege escalationMuddyWater uses various techniques to bypass UAC.
T1590.004Gather Victim Network Information: Network TopologyreconnaissanceMuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors.
T1583.006Acquire Infrastructure: Web Servicesresource developmentMuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.
T1588.002Obtain Capabilities: Toolresource developmentMuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment.
T1588.001Obtain Capabilities: Malwareresource developmentMuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals.
T1583.001Acquire Infrastructure: Domainsresource developmentMuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations.
T1027.004Obfuscated Files or Information: Compile After DeliverystealthMuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.
T1218.011System Binary Proxy Execution: Rundll32stealthMuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll.
T1027.010Obfuscated Files or Information: Command ObfuscationstealthMuddyWater has used Daniel Bohannon's Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.
T1140Deobfuscate/Decode Files or InformationstealthMuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript.
T1218.003System Binary Proxy Execution: CMSTPstealthMuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload.
T1036.005Masquerading: Match Legitimate Resource Name or LocationstealthMuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.
T1218.005System Binary Proxy Execution: MshtastealthMuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution.
T1684.001Social Engineering for Impact: ImpersonationstealthMuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan.
T1027.003Obfuscated Files or Information: SteganographystealthMuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.