MuddyWater

MITRE ATT&CK: G0069 View on attack.mitre.org

Aliases: Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill, COBALT ULSTER, ATK51, Boggy Serpens, MuddyWater, SeedWorm

First seen
2017-01-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
259 (172 malicious)
Last IoC activity
2026-09-02 02:09:10
Profile updated
2026-07-07 12:33:16

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services energy-and-utilities defense-and-aerospace

Targeted regions: country_code:ae country_code:sa country_code:ir country_code:us country_code:fr country_code:de

Context

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.

Recent IoC activity

173 malicious indicators in Maltiverse are attributed to MuddyWater (G0069). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname ns-3.open.ro 2026-09-03 1
hostname autodiscover.email 2026-09-03 1
hostname autodiscover.exchange 2026-09-03 1
hostname makemyadvertisement.com 2026-09-03 2
hostname safe.bbits.solutions 2026-09-03 2
hostname ilodges.co.uk 2026-09-03 2
hostname autoconfig.email 2026-09-03 1
hostname www.nullsecurity.net 2026-09-03 1
hostname mail.pics 2026-09-03 1
hostname printstore.com.pk 2026-09-03 2
hostname bernardkhalil.com 2026-09-03 2
hostname mimiagaengineeringgroup.com 2026-09-02 2
hostname prod.tools 2026-09-02 1
hostname webdisk.us 2026-09-02 1
hostname autodiscover.host 2026-09-02 1
hostname admin.dev 2026-09-02 1
hostname demo.bbits.solutions 2026-09-02 2
hostname autodiscover.it 2026-09-02 1
hostname dufontfaes.com 2026-09-02 2
hostname made.by 2026-09-02 1

Detection coverage

  • 30 YARA rules
  • 970 Sigma rules

Malware & tools used

  • Spearphishing Link (attack-pattern)
  • Office Template Macros (attack-pattern)
  • DLL (attack-pattern)
  • Tool (attack-pattern)
  • Mshta (attack-pattern)
  • Malicious Copy and Paste (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Internal Spearphishing (attack-pattern)
  • LSA Secrets (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Domains (attack-pattern)
  • Network Topology (attack-pattern)
  • Component Object Model (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Malware (attack-pattern)
  • CMSTP (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Domain Account (attack-pattern)
  • JavaScript (attack-pattern)
  • Web Services (attack-pattern)
  • Visual Basic (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • Palo Alto Unit 42 — Unit42 Muddying The Water Targeted Attacks In The Middle East (report)
  • cfr.org — Muddywater (report)
  • Mandiant — Iranian Threat Group Updates Ttps In Spear Phishing Campaign (report)
  • Trend Micro — Campaign Possibly Connected Muddywater Surfaces Middle East Central Asia (report)
  • Trend Micro — Another Potential Muddywater Campaign Uses Powershell Based Prb Backdoor (report)
  • Kaspersky — 88059 (report)
  • Broadcom/Symantec — Seedworm Espionage Group (report)
  • clearskysec.com — Muddywater Operations In Lebanon And Oman (report)
  • clearskysec.com — Muddywater Targets Kurdish Groups Turkish Orgs (report)
  • Cisco Talos — Recent Muddywater Associated Blackwater (report)
  • zdnet.com — New Leaks Of Iranian Cyber Espionage Operations Hit Telegram And The Dark Web (report)
  • MITRE ATT&CK — G0069 (report)
  • secureworks.com — Cobalt Ulster (report)
  • Palo Alto Unit 42 — Boggyserpens (report)
  • sentinelone.com — The New Frontline Of Geopolitics Understanding The Rise Of State Sponsored Cyber Attacks (report)
  • Trend Micro — Earth Vetala Muddywater Continues To Target Organizations In T (report)
  • Microsoft — Mercury And Dev 1084 Destructive Attack On Hybrid Environment (report)
  • proofpoint.com — Around World 90 Days State Sponsored Actors Try Clickfix (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • blog.cloudflare.com — 2026 Threat Report (report)
  • Cisco Talos — Iranian Apt Muddywater Targets Turkey (report)
  • falconfeeds.io — The Digital Redoubt Irans National Information Network Cyber Conflict (report)
  • hunt.io — Iranian Apt Infrastructure State Aligned Clusters (report)

External references