MuddyWater
G0069APT / State-SponsoredIranActive
Also known as: Earth Vetala · MERCURY · Static Kitten · Seedworm · TEMP.Zagros · Mango Sandstorm · TA450 · MuddyKrill
Overview
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.
T1566.002Spearphishing LinkInitial Access
T1137.001Office Template MacrosPersistence
T1574.001DLLStealth
T1588.002ToolResource Development
T1218.005MshtaStealth
T1204.004Malicious Copy and PasteExecution
T1047Windows Management InstrumentationExecution
T1534Internal SpearphishingLateral Movement
Malware & Tools — 21
MuddyViperMalwareWindows
STARWHALEMalwareWindows
LP-NotesMalwareWindows
POWERSTATSMalwareWindows
RcloneToolLinux / Windows / macOS
Out1ToolWindows
Tsundere BotnetMalwareLinux / macOS / Windows
PowerSploitToolWindows
Small SieveMalwareWindows
Fooder
T1003.004
LSA Secrets
Credential Access
T1566.001Spearphishing AttachmentInitial Access
T1583.001DomainsResource Development
T1590.004Network TopologyReconnaissance
T1559.001Component Object ModelExecution
T1571Non-Standard PortCommand and Control
T1059.003Windows Command ShellExecution
T1588.001MalwareResource Development
T1036.005Match Legitimate Resource Name or LocationStealth
T1087.002Domain AccountDiscovery
T1059.007JavaScriptExecution
T1583.006Web ServicesResource Development
T1059.005Visual BasicExecution
T1016System Network Configuration DiscoveryDiscovery
T1547.001Registry Run Keys / Startup FolderPersistence
T1140Deobfuscate/Decode Files or InformationStealth
T1559.002Dynamic Data ExchangeExecution
T1027.010Command ObfuscationStealth
T1027.004Compile After DeliveryStealth
T1518.001Security Software DiscoveryDiscovery
T1074.001Local Data StagingCollection
T1113Screen CaptureCollection
T1071.001Web ProtocolsCommand and Control
T1685Disable or Modify ToolsDefense Impairment
T1518Software DiscoveryDiscovery
T1083File and Directory DiscoveryDiscovery
T1548.002Bypass User Account ControlPrivilege Escalation
T1105Ingress Tool TransferCommand and Control
T1573.001Symmetric CryptographyCommand and Control
T1567.002Exfiltration to Cloud StorageExfiltration
T1555.003Credentials from Web BrowsersCredential Access
T1566PhishingInitial Access
T1560.001Archive via UtilityCollection
T1684.001ImpersonationStealth
T1049System Network Connections DiscoveryDiscovery
T1082System Information DiscoveryDiscovery
T1555Credentials from Password StoresCredential Access
T1057Process DiscoveryDiscovery
T1132.001Standard EncodingCommand and Control
T1104Multi-Stage ChannelsCommand and Control
Malware
Windows
LaZagneToolLinux / macOS / Windows
EmpireToolLinux / macOS / Windows
RemoteUtilitiesToolWindows