MuddyWater
MITRE ATT&CK: G0069 View on attack.mitre.org
Aliases: Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill, COBALT ULSTER, ATK51, Boggy Serpens, MuddyWater, SeedWorm
- First seen
- 2017-01-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 259 (172 malicious)
- Last IoC activity
- 2026-09-02 02:09:10
- Profile updated
- 2026-07-07 12:33:16
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services energy-and-utilities defense-and-aerospace
Targeted regions: country_code:ae country_code:sa country_code:ir country_code:us country_code:fr country_code:de
Context
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.
Recent IoC activity
173 malicious indicators in Maltiverse are attributed to MuddyWater (G0069). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | ns-3.open.ro | 2026-09-03 | 1 |
| hostname | autodiscover.email | 2026-09-03 | 1 |
| hostname | autodiscover.exchange | 2026-09-03 | 1 |
| hostname | makemyadvertisement.com | 2026-09-03 | 2 |
| hostname | safe.bbits.solutions | 2026-09-03 | 2 |
| hostname | ilodges.co.uk | 2026-09-03 | 2 |
| hostname | autoconfig.email | 2026-09-03 | 1 |
| hostname | www.nullsecurity.net | 2026-09-03 | 1 |
| hostname | mail.pics | 2026-09-03 | 1 |
| hostname | printstore.com.pk | 2026-09-03 | 2 |
| hostname | bernardkhalil.com | 2026-09-03 | 2 |
| hostname | mimiagaengineeringgroup.com | 2026-09-02 | 2 |
| hostname | prod.tools | 2026-09-02 | 1 |
| hostname | webdisk.us | 2026-09-02 | 1 |
| hostname | autodiscover.host | 2026-09-02 | 1 |
| hostname | admin.dev | 2026-09-02 | 1 |
| hostname | demo.bbits.solutions | 2026-09-02 | 2 |
| hostname | autodiscover.it | 2026-09-02 | 1 |
| hostname | dufontfaes.com | 2026-09-02 | 2 |
| hostname | made.by | 2026-09-02 | 1 |
Detection coverage
- 30 YARA rules
- 970 Sigma rules
Malware & tools used
- Spearphishing Link (attack-pattern)
- Office Template Macros (attack-pattern)
- DLL (attack-pattern)
- Tool (attack-pattern)
- Mshta (attack-pattern)
- Malicious Copy and Paste (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Internal Spearphishing (attack-pattern)
- LSA Secrets (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Domains (attack-pattern)
- Network Topology (attack-pattern)
- Component Object Model (attack-pattern)
- Non-Standard Port (attack-pattern)
- Windows Command Shell (attack-pattern)
- Malware (attack-pattern)
- CMSTP (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Domain Account (attack-pattern)
- JavaScript (attack-pattern)
- Web Services (attack-pattern)
- Visual Basic (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- Palo Alto Unit 42 — Unit42 Muddying The Water Targeted Attacks In The Middle East (report)
- cfr.org — Muddywater (report)
- Mandiant — Iranian Threat Group Updates Ttps In Spear Phishing Campaign (report)
- Trend Micro — Campaign Possibly Connected Muddywater Surfaces Middle East Central Asia (report)
- Trend Micro — Another Potential Muddywater Campaign Uses Powershell Based Prb Backdoor (report)
- Kaspersky — 88059 (report)
- Broadcom/Symantec — Seedworm Espionage Group (report)
- clearskysec.com — Muddywater Operations In Lebanon And Oman (report)
- clearskysec.com — Muddywater Targets Kurdish Groups Turkish Orgs (report)
- Cisco Talos — Recent Muddywater Associated Blackwater (report)
- zdnet.com — New Leaks Of Iranian Cyber Espionage Operations Hit Telegram And The Dark Web (report)
- MITRE ATT&CK — G0069 (report)
- secureworks.com — Cobalt Ulster (report)
- Palo Alto Unit 42 — Boggyserpens (report)
- sentinelone.com — The New Frontline Of Geopolitics Understanding The Rise Of State Sponsored Cyber Attacks (report)
- Trend Micro — Earth Vetala Muddywater Continues To Target Organizations In T (report)
- Microsoft — Mercury And Dev 1084 Destructive Attack On Hybrid Environment (report)
- proofpoint.com — Around World 90 Days State Sponsored Actors Try Clickfix (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- blog.cloudflare.com — 2026 Threat Report (report)
- Cisco Talos — Iranian Apt Muddywater Targets Turkey (report)
- falconfeeds.io — The Digital Redoubt Irans National Information Network Cyber Conflict (report)
- hunt.io — Iranian Apt Infrastructure State Aligned Clusters (report)
External references
- mitre-attack — G0069
- Cloudflare 2026 Threat Report New Threat Actors March 2026
- MERCURY
- Static Kitten
- MuddyKrill
- TEMP.Zagros
- Mango Sandstorm
- TA450
- Seedworm
- Earth Vetala
- MuddyWater
- ClearSky MuddyWater Nov 2018
- ClearSky MuddyWater June 2019
- CYBERCOM Iranian Intel Cyber January 2022
- ESET_MuddyWater_Dec2025
- FalconFeeds_Iran_Mar2026
- DHS CISA AA22-055A MuddyWater February 2022
- Huntio_IranInfra_Mar2026
- Unit 42 MuddyWater Nov 2017
- Talos MuddyWater Jan 2022