Also known as: Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill, SectorD02, COBALT ULSTER, G0069, ATK51, Boggy Serpens, MUDDYCOAST, MUDDY ION
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. (Citation: FalconFeeds_Iran_Mar2026)(Citation: Huntio_IranInfra_Mar2026)(Citation: Unit 42 MuddyWater Nov 2017)(Citation: Symantec MuddyWater Dec 2018)(Citation: ClearSky MuddyWater Nov 2018)(Citation: ClearSky MuddyWater June 2019)(Citation: Reaqta MuddyWater November 2017)(Citation: DHS CISA AA22-055A MuddyWater February 2022)(Citation: Talos MuddyWater Jan 2022)(Citation: NaumaanProofpoint_GlobalClickFix_April2025)(Citation: ESET_MuddyWater_Dec2025)(Citation: SymantecCarbonBlack_Seedworm_Mar2026)
BlackWater
Targeted Sectors
Targeted Countries / Regions
Executive Summary
MuddyWater is a cyber espionage group assessed to be linked to Iran's Ministry of Intelligence and Security (MOIS). The group has targeted government and defense sectors globally since at least 2017, with recent activity involving the use of commercial satellite internet (Starlink) for command and control communication. MuddyWater employs advanced persistent threat tactics, including spear-phishing campaigns and malware deployment, to steal sensitive information.
Goals & Targeting
MuddyWater's primary motivation is espionage, targeting government agencies, defense organizations, and critical infrastructure sectors across various regions. The group appears to be focused on stealing sensitive information from Middle Eastern countries and global entities aligned with Iranian interests. MuddyWater's victims include telecommunications companies, local governments, and energy sector organizations.
Enhanced Description
MuddyWater, also known as Earth Vetala, TA450, and other aliases, is a sophisticated cyber espionage group associated with Iran. The group has targeted various sectors, including telecommunications, government, finance, defense, and energy, across the Middle East, Asia, Africa, Europe, and North America. MuddyWater is known for its long-standing campaigns targeting sensitive information from government agencies and private organizations. The group has exhibited a preference for using NameCheap and Hosterdaddy Private Limited (AS136557) infrastructure and has been observed reusing domains dating back to October 2025. Recent activity includes the use of commercial satellite internet, such as Starlink, for C2 communication. MuddyWater's tactics include spear-phishing attacks with malicious attachments,Living-off-the-land (LoL) behaviors, and custom malware deployment. The group is highly regarded in the cyber threat landscape, with multiple attributions to its activities globally.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
MuddyWater has conducted numerous campaigns since its emergence, including highly targeted operations against Middle Eastern governments and energy sector entities. The group's recent tactics have involved SolarWinds-style infrastructure compromises and the use of Starlink for C2 communication, making it more challenging to detect and attribute their activities. MuddyWater is known for its patient and methodical approach to espionage, often maintaining long-term access to victim networks to extract maximum intelligence value.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in MuddyWater's association with Iran's MOIS based on multiple attributions, but some details about its exact origins and specific campaigns remain unclear.
BlackWater
Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign
Imported from MISP event #480 (6265f228-1b56-46ef-9bd7-dbd3d02048ef).
Mar 21, 2024
TLP:CLEARNo observed data linked yet.
68
Techniques
14
Tools
4
Campaigns
41
IOCs
0
Observed Data
14
Tactics