Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors MuddyWater

Also known as: Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill, SectorD02, COBALT ULSTER, G0069, ATK51, Boggy Serpens, MUDDYCOAST, MUDDY ION

Description

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. (Citation: FalconFeeds_Iran_Mar2026)(Citation: Huntio_IranInfra_Mar2026)(Citation: Unit 42 MuddyWater Nov 2017)(Citation: Symantec MuddyWater Dec 2018)(Citation: ClearSky MuddyWater Nov 2018)(Citation: ClearSky MuddyWater June 2019)(Citation: Reaqta MuddyWater November 2017)(Citation: DHS CISA AA22-055A MuddyWater February 2022)(Citation: Talos MuddyWater Jan 2022)(Citation: NaumaanProofpoint_GlobalClickFix_April2025)(Citation: ESET_MuddyWater_Dec2025)(Citation: SymantecCarbonBlack_Seedworm_Mar2026)

TTP Summary

BlackWater

Goals & Targeting

Targeted Sectors

Government
Defense

Targeted Countries / Regions

middle_east

AI Analysis

· 1 week ago

Executive Summary

MuddyWater is a cyber espionage group assessed to be linked to Iran's Ministry of Intelligence and Security (MOIS). The group has targeted government and defense sectors globally since at least 2017, with recent activity involving the use of commercial satellite internet (Starlink) for command and control communication. MuddyWater employs advanced persistent threat tactics, including spear-phishing campaigns and malware deployment, to steal sensitive information.

Goals & Targeting

MuddyWater's primary motivation is espionage, targeting government agencies, defense organizations, and critical infrastructure sectors across various regions. The group appears to be focused on stealing sensitive information from Middle Eastern countries and global entities aligned with Iranian interests. MuddyWater's victims include telecommunications companies, local governments, and energy sector organizations.

Enhanced Description

MuddyWater, also known as Earth Vetala, TA450, and other aliases, is a sophisticated cyber espionage group associated with Iran. The group has targeted various sectors, including telecommunications, government, finance, defense, and energy, across the Middle East, Asia, Africa, Europe, and North America. MuddyWater is known for its long-standing campaigns targeting sensitive information from government agencies and private organizations. The group has exhibited a preference for using NameCheap and Hosterdaddy Private Limited (AS136557) infrastructure and has been observed reusing domains dating back to October 2025. Recent activity includes the use of commercial satellite internet, such as Starlink, for C2 communication. MuddyWater's tactics include spear-phishing attacks with malicious attachments,Living-off-the-land (LoL) behaviors, and custom malware deployment. The group is highly regarded in the cyber threat landscape, with multiple attributions to its activities globally.

Key Capabilities

  • Spear-phishing campaigns
  • Malware deployment
  • Living-off-the-land techniques
  • Reconnaissance and data exfiltration
  • Commercial satellite internet usage for C2
  • Reuse of infrastructure domains over time

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Reconnaissance
Exfiltration
Impact

ATT&CK Techniques

T1053.005: Scheduled Task
T1560.001: Archive via Utility
T1113: Screen Capture
T1132.001: Standard Encoding
T1087.002: Domain Account
T1059.007: JavaScript
T1074.001: Local Data Staging
T1036.005: Match Legitimate Resource Name or Location
T1003.004: LSA Secrets
T1204.002: Malicious File
T1573.001: Symmetric Cryptography
T1566.001: Spearphishing Attachment

Software / Tooling

Tsundere Botnet
RustyWater
SHARPSTATS

Campaigns & Victims

MuddyWater has conducted numerous campaigns since its emergence, including highly targeted operations against Middle Eastern governments and energy sector entities. The group's recent tactics have involved SolarWinds-style infrastructure compromises and the use of Starlink for C2 communication, making it more challenging to detect and attribute their activities. MuddyWater is known for its patient and methodical approach to espionage, often maintaining long-term access to victim networks to extract maximum intelligence value.

IOC Patterns

  • hash-md5, 37c3f5b3c814e2c014abc1210e8e69a2
  • url, ws.onehub.com/files/7f9dxtt6

Recommended Actions

  • Implement robust email filtering and anti-phishing solutions to detect spear-phishing attempts.
  • Monitor network traffic for signs of data exfiltration or unauthorized C2 communication.
  • Conduct regular security audits and implement multi-factor authentication (MFA) for critical systems.
  • Secure remote desktop protocol (RDP) access and limit exposed services on the internet.
  • Educate employees about phishing tactics and suspicious email activity.

Suggested Tags

APT
Espionage
Government
Defense
Middle East

Confidence Assessment

High confidence in MuddyWater's association with Iran's MOIS based on multiple attributions, but some details about its exact origins and specific campaigns remain unclear.

ATT&CK Techniques

Command & Control
10 techniques
Credential Access
6 techniques
Discovery
9 techniques
Execution
13 techniques
Initial Access
4 techniques
Resource Development
4 techniques
Stealth
10 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 7 IPv4 Address 9 URL 3 MD5 Hash 1

References

  1. Cloudflare 2026 Threat Report New Threat Actors March 2026 — Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
  2. ClearSky MuddyWater Nov 2018 — ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.
  3. ClearSky MuddyWater June 2019 — ClearSky. (2019, June). Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal. Retrieved May 14, 2020.
  4. CYBERCOM Iranian Intel Cyber January 2022 — Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.
  5. ESET_MuddyWater_Dec2025 — ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.
  6. FalconFeeds_Iran_Mar2026 — FalconFeeds.io. (2026, March 5). The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict. Retrieved March 9, 2026.
  7. DHS CISA AA22-055A MuddyWater February 2022 — FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.
  8. Huntio_IranInfra_Mar2026 — Hunt.io. (2026, March 4). Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation. Retrieved April 16, 2026.
  9. Unit 42 MuddyWater Nov 2017 — Lancaster, T.. (2017, November 14). Muddying the Water: Targeted Attacks in the Middle East. Retrieved March 15, 2018.
  10. Talos MuddyWater Jan 2022 — Malhortra, A and Ventura, V. (2022, January 31). Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables. Retrieved June 22, 2022.
  11. Anomali Static Kitten February 2021 — Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.
  12. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  13. Proofpoint TA450 Phishing March 2024 — Miller, J. et al. (2024, March 21). Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign. Retrieved March 27, 2024.
  14. NaumaanProofpoint_GlobalClickFix_April2025 — Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.
  15. Trend Micro Muddy Water March 2021 — Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.
  16. Reaqta MuddyWater November 2017 — Reaqta. (2017, November 22). A dive into MuddyWater APT targeting Middle-East. Retrieved May 18, 2020.
  17. FireEye MuddyWater Mar 2018 — Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.
  18. Symantec MuddyWater Dec 2018 — Symantec DeepSight Adversary Intelligence Team. (2018, December 10). Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms. Retrieved December 14, 2018.
  19. SymantecCarbonBlack_Seedworm_Mar2026 — Threat Hunter Team. (2026, March 5). Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company. Retrieved March 5, 2026.

Intel Summary

68

Techniques

14

Tools

4

Campaigns

41

IOCs

0

Observed Data

14

Tactics

Tags

APT
Backdoor / C2
Government Targeting
Espionage
Government
Defense
Middle East

Details

MITRE ID
G0069
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--269e8108-68c6-4f99-b911-14b2e765dec2
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.