LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0069: MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).CitationCYBERCOM Iranian Intel Cyber January 2022 Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. CitationFalconFeeds_Iran_Mar2026CitationHuntio_IranInfra_Mar2026CitationUnit 42 MuddyWater Nov 2017CitationSymantec MuddyWater Dec 2018CitationClearSky MuddyWater Nov 2018CitationClearSky MuddyWater June 2019CitationReaqta MuddyWater November 2017CitationDHS CISA AA22-055A MuddyWater February 2022CitationTalos MuddyWater Jan 2022CitationNaumaanProofpoint_GlobalClickFix_April2025CitationESET_MuddyWater_Dec2025CitationSymantecCarbonBlack_Seedworm_Mar2026

EnterpriseG0069GroupObject v7.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

MuddyWater matters because ATT&CK describes it as an Iran MOIS-subordinate cyber espionage group with long-running targeting across government and private sectors, including telecommunications, local government, finance, defense, and oil and natural gas. For leaders, the practical issue is not the name alone; it is whether the organization can recognize credential theft, PowerShell/script-based tradecraft, legitimate remote administration tool abuse, cloud-sync exfiltration paths, and unusual command-and-control infrastructure before an investigation becomes dependent on incomplete logs.

Executive priority

Prioritize MuddyWater as a readiness benchmark for espionage-oriented intrusion response: identity hardening, Windows endpoint visibility, remote access governance, and evidence retention. Organizations in or supporting the sectors and regions named by ATT&CK should ask whether their SOC can prove coverage for credential access, backdoors/loaders, post-exploitation frameworks, and remote administration tools that may appear legitimate. This also supports audit and compliance discussions because the decisive evidence is often control validation: who can access credentials, what remote tools are approved, what script execution is logged, and whether incident responders can reconstruct lateral movement and data movement.

Technical view

ATT&CK provides no group-level detection text or platforms for the intrusion-set object, but relationships show extensive use of Windows-focused and cross-platform tooling. Defenders should validate detections and response playbooks around Mimikatz, LaZagne, LSASS memory access, LSA Secrets access, PowerSploit, Empire, Koadic, CrackMapExec, ConnectWise, RemoteUtilities, Rclone, and multiple MuddyWater-associated backdoors/loaders such as POWERSTATS, SHARPSTATS, PowGoop, Mori, Small Sieve, STARWHALE, MuddyViper, Fooder, LP-Notes, and RustyWater. The technical emphasis should be on behavior and control-plane evidence rather than only static indicators: credential dumping attempts, suspicious PowerShell or Windows Script Host activity, unexpected remote admin sessions, unusual cloud storage synchronization, suspicious loaders/backdoors, and C2 patterns including infrastructure choices noted in ATT&CK such as reused domains and commercial satellite internet use for C2 in late 2025 and early 2026.

Likely telemetry

  • Windows endpoint process creation, command-line, script block, module, and PowerShell logging where applicable
  • Security event logs and EDR telemetry for LSASS access, credential dumping, LSA Secrets access, and suspicious handle access
  • Registry and memory-related telemetry relevant to credential material access
  • Remote administration tool inventory and session logs for ConnectWise, RemoteUtilities, and other approved or unapproved RAT usage
  • Network DNS, proxy, firewall, TLS, and egress telemetry for reused domains, unusual C2 destinations, and beacon-like traffic

Detection direction

  • Map existing detections to the related ATT&CK techniques and software rather than relying on the MuddyWater name as a detection object.
  • Validate that LSASS memory and LSA Secrets access alerts distinguish authorized administrative/security tooling from suspicious credential access attempts.
  • Tune for PowerShell, Windows Script Host, .NET, Python, C/C++, Rust, Node.js, and JavaScript execution patterns only where supported by local telemetry and the related tools; avoid brittle filename-only logic.
  • Review allowlists for legitimate remote administration tools because ConnectWise and RemoteUtilities may be expected in some environments and suspicious in others.
  • Correlate remote admin sessions, credential access, and new or unusual outbound C2 to reduce false positives and improve incident confidence.

Mitigation priorities

  • Start with identity controls: reduce credential exposure, protect privileged accounts, monitor service accounts, and enforce least privilege for administrative access.
  • Harden Windows endpoints against credential dumping and script abuse through baseline configuration, logging, and controlled administrative tool use.
  • Govern remote administration software with explicit approval, inventory, MFA where applicable, session logging, and rapid revocation processes.
  • Restrict and monitor outbound traffic, especially to newly observed or untrusted infrastructure, cloud storage services, and unusual C2 paths.
  • Maintain incident response playbooks for credential theft and remote access abuse, including password rotation, token/session revocation, host isolation, and forensic preservation.
Additional notes and limits

The most defensible Glexia use of this ATT&CK object is as a control-validation scenario for espionage tradecraft. The relationships emphasize credential access, post-exploitation frameworks, backdoors/loaders, remote administration tools, and data movement tooling. Because several tools are open-source or legitimate administration utilities, high-quality detection depends on context: asset role, user identity, parent process, command line, network destination, and whether the tool is approved in the environment.

The supplied group object has no official detection text, no listed tactics, and no group-level platforms. Platform and technique guidance above is derived from the supplied relationships only. Local relevance depends on sector, geography, technology stack, approved remote access tools, logging depth, and retention. This take should not be read as a claim that MuddyWater is currently targeting any specific organization.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).CitationCYBERCOM Iranian Intel Cyber January 2022 Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. CitationFalconFeeds_Iran_Mar2026CitationHuntio_IranInfra_Mar2026CitationUnit 42 MuddyWater Nov 2017CitationSymantec MuddyWater Dec 2018CitationClearSky MuddyWater Nov 2018CitationClearSky MuddyWater June 2019CitationReaqta MuddyWater November 2017CitationDHS CISA AA22-055A MuddyWater February 2022CitationTalos MuddyWater Jan 2022CitationNaumaanProofpoint_GlobalClickFix_April2025CitationESET_MuddyWater_Dec2025CitationSymantecCarbonBlack_Seedworm_Mar2026

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
7.0
Created
Modified
Raw hash
7ef8320b44a969ac...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.