MuddyWater
MISPNation-state
IR
Unknown
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at least 2017, [MuddyWater](https://attack.mitre.org/groups/G0069) has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. [MuddyWater](https://attack.mitre.org/groups/G0069) has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, [MuddyWater](https://attack.mitre.org/groups/G0069) used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. (Citation: FalconFeeds_Iran_Mar2026)(Citation: Huntio_IranInfra_Mar2026)(Citation: Unit 42 MuddyWater Nov 2017)(Citation: Symantec MuddyWater Dec 2018)(Citation: ClearSky MuddyWater Nov 2018)(Citation: ClearSky MuddyWater June 2019)(Citation: Reaqta MuddyWater November 2017)(Citation: DHS CISA AA22-055A MuddyWater February 2022)(Citation: Talos MuddyWater Jan 2022)(Citation: NaumaanProofpoint_GlobalClickFix_April2025)(Citation: ESET_MuddyWater_Dec2025)(Citation: SymantecCarbonBlack_Seedworm_Mar2026)
Techniques Used (70)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1003.001 | LSASS Memory | - |
| T1003.004 | LSA Secrets | - |
| T1003.005 | Cached Domain Credentials | - |
| T1016 | System Network Configuration Discovery | - |
| T1027.003 | Steganography | - |
| T1027.004 | Compile After Delivery | - |
| T1027.010 | Command Obfuscation | - |
| T1033 | System Owner/User Discovery | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1041 | Exfiltration Over C2 Channel | - |
| T1047 | Windows Management Instrumentation | - |
| T1049 | System Network Connections Discovery | - |
| T1053.005 | Scheduled Task | - |
| T1057 | Process Discovery | - |
| T1059.001 | PowerShell | - |
References (10)
- unit42.paloaltonetworks.com - Unit42 Muddying The Water Targeted Attacks In The Middle East
- cfr.org - Muddywater
- fireeye.com - Iranian Threat Group Updates Ttps In Spear Phishing Campaign
- blog.trendmicro.com - Campaign Possibly Connected Muddywater Surfaces Middle East Central Asia
- blog.trendmicro.com - Another Potential Muddywater Campaign Uses Powershell Based Prb Backdoor
- securelist.com - 88059
- symantec.com - Seedworm Espionage Group
- clearskysec.com - MuddyWater Operations In Lebanon And Oman.pdf
- clearskysec.com - Muddywater Targets Kurdish Groups Turkish Orgs
- blog.talosintelligence.com - Recent Muddywater Associated Blackwater
Aliases (5263)
Related Malware (21)
Metadata
| ID: | 156 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/06/2026 16:00 |