MuddyWater is a prolific Iranian MOIS-subordinate cyber-espionage group that has targeted government, telecom, defense, and energy organizations across the Middle East since 2017, with heavy focus on Gulf states and Israel.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
+107 more relationships — see the relationships browser.
MuddyWater first surfaced publicly in 2017 and was formally attributed by U.S. Cyber Command in January 2022 as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS). The group is assessed to function as one of Iran's most active regional espionage arms, blending intelligence collection with occasional access-brokering for other Iranian clusters.
Across its lifetime MuddyWater has favored living-off-the-land tradecraft: malicious documents with macro or lure content, PowerShell-based footholds, and heavy abuse of legitimate remote-management tools (Atera, ScreenConnect, Syncro, RemoteUtilities) for command-and-control and persistence. The group also runs custom implants and has repeatedly refreshed its C2 infrastructure, showing a preference for NameCheap-registered domains and specific hosting providers.
MENA targeting is central to MuddyWater's mission. Reporting consistently places victims in the UAE, Saudi Arabia, Israel, Turkey, Iraq, Jordan, and Egypt, spanning telecommunications, local government, finance, defense, and oil-and-gas sectors. CISA's AA22-055A advisory (February 2022) documented its Middle East and broader campaigns in detail.
The group remains highly active into 2025–2026. MITRE ATT&CK notes MuddyWater reusing domains dating to October 2025 and, in late 2025 and early 2026, adopting commercial satellite internet (Starlink) for C2 — an assessed attempt to complicate infrastructure tracking and network-based detection. ESET (December 2025) and Symantec/Carbon Black (March 2026, tracked as Seedworm) reported continued regional operations, and researchers have documented operational overlaps with the HEXANE/Lyceum cluster where MuddyWater likely acts as an initial-access broker. In January 2026, Group-IB documented Operation Olalampo, a MENA-wide MuddyWater campaign introducing the GhostFetch/HTTP_VIP downloaders, GhostBackDoor implant, and a Rust-based CHAR backdoor using Telegram-bot C2, with indications of AI-assisted development.