Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill
68
techniques
21
software
11,841
corpus matches
profile
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.
techniques
68 attributed · most-instrumented first
software
21 malware & tools attributed
Mimikatz
S0002
PowerSploit
S0194
POWERSTATS
S0223
Koadic
S0250
LaZagne
S0349
Empire
S0363
SHARPSTATS
S0450
CrackMapExec
S0488
ConnectWise
S0591
RemoteUtilities
S0592
read this carefully
11,841 corpus matches is not attribution
That count is indicators which exhibit techniques MuddyWater is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+56 more techniques
Out1
S0594
Small Sieve
S1035
STARWHALE
S1037
Rclone
S1040
PowGoop
S1046
Mori
S1047
MuddyViper
S9032
Fooder
S9033
Tsundere Botnet
S9034
LP-Notes
S9036
RustyWater
S9037
showing 30 of 11,841
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.