FORENSIA

THREAT_ACTOR · G0069

MuddyWater

Also known as: MuddyWater, Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill

Profile

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.

MITRE ATT&CK ↗

Techniques

68 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.004 LSA SecretsT1003.005 Cached Domain CredentialsT1016 System Network Configuration DiscoveryT1027.003 SteganographyT1027.004 Compile After DeliveryT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1036.005 Match Legitimate Resource Name or LocationT1041 Exfiltration Over C2 ChannelT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.006 PythonT1059.007 JavaScriptT1071.001 Web ProtocolsT1074.001 Local Data StagingT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.002 Domain AccountT1090 ProxyT1090.002 External ProxyT1102.002 Bidirectional CommunicationT1104 Multi-Stage ChannelsT1105 Ingress Tool TransferT1113 Screen CaptureT1132.001 Standard EncodingT1137.001 Office Template MacrosT1140 Deobfuscate/Decode Files or InformationT1190 Exploit Public-Facing ApplicationT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1204.004 Malicious Copy and PasteT1210 Exploitation of Remote ServicesT1218.003 CMSTPT1218.005 MshtaT1218.011 Rundll32T1219.002 Remote Desktop SoftwareT1518 Software DiscoveryT1518.001 Security Software DiscoveryT1534 Internal SpearphishingT1547.001 Registry Run Keys / Startup FolderT1548.002 Bypass User Account ControlT1552.001 Credentials In FilesT1555 Credentials from Password StoresT1555.003 Credentials from Web BrowsersT1559.001 Component Object ModelT1559.002 Dynamic Data ExchangeT1560.001 Archive via UtilityT1566 PhishingT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1567.002 Exfiltration to Cloud StorageT1571 Non-Standard PortT1573.001 Symmetric CryptographyT1574.001 DLLT1583.001 DomainsT1583.006 Web ServicesT1588.001 MalwareT1588.002 ToolT1590.004 Network TopologyT1684.001 ImpersonationT1685 Disable or Modify Tools

Software

21 malware/tools attributed to this actor.

MimikatzPowerSploitPOWERSTATSKoadicLaZagneEmpireSHARPSTATSCrackMapExecConnectWiseRemoteUtilitiesOut1Small SieveSTARWHALERclonePowGoopMoriMuddyViperFooderTsundere BotnetLP-NotesRustyWater

Related corpus activity

10,465 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to MuddyWater.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,465.