LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0069: MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).[1] Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. [2][3][4][5][6][7][8][9][10][11][12][13]

EnterpriseG0069GroupObject v7.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0069: MuddyWater describes [MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at least 2017, [MuddyWater](https://attack.mitre.org/groups/G0069) has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the...

Executive priority

G0069: MuddyWater is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0069: MuddyWater by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0069: MuddyWater appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).[1] Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. [2][3][4][5][6][7][8][9][10][11][12][13]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

60 rows
DomainIDNameRelationship / procedure
EnterpriseT1566.002Spearphishing LinkSub-technique

MuddyWater has sent targeted spearphishing e-mails with malicious links.[14][15][16]

EnterpriseT1137.001Office Template MacrosSub-technique

MuddyWater has used a Word Template, Normal.dotm, for persistence.[8]

EnterpriseT1574.001DLLSub-technique

MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware.[9]

EnterpriseT1588.002ToolSub-technique

MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment.[14]Citationgroup-ib_muddywater_infra[12][11]

EnterpriseT1218.005MshtaSub-technique

MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution.[17]CitationSecurelist MuddyWater Oct 2018

EnterpriseT1204.004Malicious Copy and PasteSub-technique

MuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code.[11]

EnterpriseT1047Windows Management Instrumentation

MuddyWater has used malware that leveraged WMI for execution and querying host information.CitationSecurelist MuddyWater Oct 2018[6]CitationTalos MuddyWater May 2019[9]

EnterpriseT1534Internal Spearphishing

MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails.[2]

EnterpriseT1003.004LSA SecretsSub-technique

MuddyWater has performed credential dumping with LaZagne.[4][5]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients.[4][17]CitationSecurelist MuddyWater Oct 2018[7][14][15][9][16][12]CitationSOCRadar_MuddyWaterDindoor_Mar2026 MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.CitationCloudSEK_RustyWater_Jan2026

EnterpriseT1583.001DomainsSub-technique

MuddyWater has established domains, some of which appeared to spoof legitimate domains for use in operations.[11]

EnterpriseT1590.004Network TopologySub-technique

MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors.CitationFalconFeeds_MuddyWaterPSRust_Mar2026

EnterpriseT1559.001Component Object ModelSub-technique

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.CitationSecurelist MuddyWater Oct 2018[7][9]

EnterpriseT1571Non-Standard Port

MuddyWater has used ports 8043 and 8848 for botnet C2 communication.CitationFalconFeeds_MuddyWaterPSRust_Mar2026

EnterpriseT1059.003Windows Command ShellSub-technique

MuddyWater has used a custom tool for creating reverse shells.[5]

EnterpriseT1588.001MalwareSub-technique

MuddyWater has used publicly available malware for operations, likely to blend in with other cybercriminals.[3]

EnterpriseT1218.003CMSTPSub-technique

MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload.[17]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.[17]CitationTalos MuddyWater May 2019[14]

EnterpriseT1087.002Domain AccountSub-technique

MuddyWater has used cmd.exe net user /domain to enumerate domain users.[15]

EnterpriseT1059.007JavaScriptSub-technique

MuddyWater has used JavaScript files to execute its POWERSTATS payload.[6][17][9]

EnterpriseT1583.006Web ServicesSub-technique

MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.[14][15][16][12]

EnterpriseT1059.005Visual BasicSub-technique

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.[17]CitationMuddyWater TrendMicro June 2018CitationSecurelist MuddyWater Oct 2018[5][6][7][8][15][10]

EnterpriseT1016System Network Configuration Discovery

MuddyWater has used malware to collect the victim’s IP address and domain name.CitationSecurelist MuddyWater Oct 2018

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.[17]CitationSecurelist MuddyWater Oct 2018CitationTalos MuddyWater May 2019[8][15][10]

EnterpriseT1140Deobfuscate/Decode Files or Information

MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript.[17]CitationMuddyWater TrendMicro June 2018[6][10]

EnterpriseT1559.002Dynamic Data ExchangeSub-technique

MuddyWater has used malware that can execute PowerShell scripts via DDE.CitationSecurelist MuddyWater Oct 2018

EnterpriseT1027.010Command ObfuscationSub-technique

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts.[4]CitationGitHub Invoke-Obfuscation The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.[4][17]CitationSecurelist MuddyWater Oct 2018CitationTalos MuddyWater May 2019[7][15][10]

EnterpriseT1027.004Compile After DeliverySub-technique

MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.[6]

EnterpriseT1518.001Security Software DiscoverySub-technique

MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers.CitationSecurelist MuddyWater Oct 2018

EnterpriseT1074.001Local Data StagingSub-technique

MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder.[10]

EnterpriseT1113Screen Capture

MuddyWater has used malware that can capture screenshots of the victim’s machine.CitationSecurelist MuddyWater Oct 2018

EnterpriseT1071.001Web ProtocolsSub-technique

MuddyWater has used HTTP for C2 communications.[7][15]

EnterpriseT1685Disable or Modify Tools

MuddyWater can disable the system's local proxy settings.[15]

EnterpriseT1518Software Discovery

MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine.[15]

EnterpriseT1083File and Directory Discovery

MuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords "Kasper," "Panda," or "ESET."CitationSecurelist MuddyWater Oct 2018

EnterpriseT1548.002Bypass User Account ControlSub-technique

MuddyWater uses various techniques to bypass UAC.[6][11]

EnterpriseT1105Ingress Tool Transfer

MuddyWater has used malware that can upload additional files to the victim’s machine.CitationSecurelist MuddyWater Oct 2018[6][8][15] MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.[11]

EnterpriseT1573.001Symmetric CryptographySub-technique

MuddyWater has used AES to encrypt C2 responses.[10]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone.CitationSOCRadar_MuddyWaterDindoor_Mar2026

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.[5][15]

EnterpriseT1566Phishing

MuddyWater has sent phishing emails to targets from the email address support@microsoftonlines[.]com.[11]

EnterpriseT1560.001Archive via UtilitySub-technique

MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded.[5]

EnterpriseT1684.001ImpersonationSub-technique

MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft.[11] MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell.CitationCloudSEK_RustyWater_Jan2026

EnterpriseT1059.006PythonSub-technique

MuddyWater has developed tools in Python including Out1.[15]

EnterpriseT1049System Network Connections Discovery

MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine.[15]

EnterpriseT1082System Information Discovery

MuddyWater has used malware that can collect the victim’s OS version and machine name.CitationSecurelist MuddyWater Oct 2018CitationTalos MuddyWater May 2019[8][15][10]

EnterpriseT1555Credentials from Password Stores

MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email.[4][5][15]

EnterpriseT1057Process Discovery

MuddyWater has used malware to obtain a list of running processes on the system.CitationSecurelist MuddyWater Oct 2018[7]

EnterpriseT1132.001Standard EncodingSub-technique

MuddyWater has used tools to encode C2 communications including Base64 encoding.[7][15]

EnterpriseT1104Multi-Stage Channels

MuddyWater has used one C2 to obtain enumeration scripts and monitor web logs, but a different C2 to send data back.CitationTalos MuddyWater May 2019

EnterpriseT1090Proxy

MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France.[2]

EnterpriseT1204.001Malicious LinkSub-technique

MuddyWater has distributed URLs in phishing e-mails that link to lure documents.[14][15][16]

EnterpriseT1027.003SteganographySub-technique

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.[6]

EnterpriseT1003.001LSASS MemorySub-technique

MuddyWater has performed credential dumping with Mimikatz and procdump64.exe.[4][5][15]

EnterpriseT1053.005Scheduled TaskSub-technique

MuddyWater has used scheduled tasks to establish persistence.[8]

EnterpriseT1090.002External ProxySub-technique

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location.[5] MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2).[8][15] MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.[12]

EnterpriseT1204.002Malicious FileSub-technique

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails.[4][17]CitationSecurelist MuddyWater Oct 2018CitationTalos MuddyWater May 2019[7][8][14][15][9][10][16] Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.CitationCloudSEK_RustyWater_Jan2026

EnterpriseT1033System Owner/User Discovery

MuddyWater has used malware that can collect the victim’s username.CitationSecurelist MuddyWater Oct 2018[15]

EnterpriseT1219.002Remote Desktop SoftwareSub-technique

MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration.[15][14][16]Citationgroup-ib_muddywater_infra[2][11]CitationFalconFeeds_MuddyWaterPSRust_Mar2026

EnterpriseT1041Exfiltration Over C2 Channel

MuddyWater has used C2 infrastructure to receive exfiltrated data.[8]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
MalwareEnterprise

S9034: Tsundere Botnet

Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script. It leverages Node.js and JavaScript for payload delivery and execution, and uses smart contracts on the blockchain to host command and control (C2) addresses. Tsundere Botnet is attributed to a likely Russian-speaking threat actor.

A variant named DinDoor has been linked to MuddyWater operations and uses the Deno runtime for execution rather than Node.js.[1][2][3][4]

LinuxmacOSWindows
ToolEnterprise

S0194: PowerSploit

PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration. [1] [2] [3]

Windows
MalwareEnterprise

S9033: Fooder

Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5 proxy utility, the open-source HackBrowserData infostealer, or the MuddyViper backdoor. Fooder has frequently masqueraded as an entertainment executable, such as the Snake game (e.g., `Snake_Game.exe`).[1]

Windows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
7.0
Created
Modified
Raw hash
ef4b64625cf3959a...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.27.0Current bundleef4b64625cf3…
19.17.0Older bundle7ef8320b44a9…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CYBERCOM Iranian Intel Cyber January 2022

    Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.

    Open source URL
  2. [2]
    FalconFeeds_Iran_Mar2026

    FalconFeeds.io. (2026, March 5). The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict. Retrieved March 9, 2026.

    Open source URL
  3. [3]
    Huntio_IranInfra_Mar2026

    Hunt.io. (2026, March 4). Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation. Retrieved April 16, 2026.

    Open source URL
  4. [4]
    Unit 42 MuddyWater Nov 2017

    Lancaster, T.. (2017, November 14). Muddying the Water: Targeted Attacks in the Middle East. Retrieved March 15, 2018.

    Open source URL
  5. [5]
    Symantec MuddyWater Dec 2018

    Symantec DeepSight Adversary Intelligence Team. (2018, December 10). Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms. Retrieved December 14, 2018.

    Open source URL
  6. [6]
    ClearSky MuddyWater Nov 2018

    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

    Open source URL
  7. [7]
    ClearSky MuddyWater June 2019

    ClearSky. (2019, June). Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal. Retrieved May 14, 2020.

    Open source URL
  8. [8]
    Reaqta MuddyWater November 2017

    Reaqta. (2017, November 22). A dive into MuddyWater APT targeting Middle-East. Retrieved May 18, 2020.

    Open source URL
  9. [9]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  10. [10]
    Talos MuddyWater Jan 2022

    Malhortra, A and Ventura, V. (2022, January 31). Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables. Retrieved June 22, 2022.

    Open source URL
  11. [11]
    NaumaanProofpoint_GlobalClickFix_April2025

    Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.

    Open source URL
  12. [12]
    ESET_MuddyWater_Dec2025

    ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.

    Open source URL
  13. [13]
    SymantecCarbonBlack_Seedworm_Mar2026

    Threat Hunter Team. (2026, March 5). Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company. Retrieved March 5, 2026.

    Open source URL
  14. [14]
    Anomali Static Kitten February 2021

    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

    Open source URL
  15. [15]
    Trend Micro Muddy Water March 2021

    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

    Open source URL
  16. [16]
    Proofpoint TA450 Phishing March 2024

    Miller, J. et al. (2024, March 21). Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign. Retrieved March 27, 2024.

    Open source URL
  17. [17]
    FireEye MuddyWater Mar 2018

    Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

    Open source URL
  18. [18]
    Cloudflare 2026 Threat Report New Threat Actors March 2026

    Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.

    Open source URL
  19. [19]
    Earth Vetala

    (Citation: Trend Micro Muddy Water March 2021)

  20. [20]
    MERCURY

    (Citation: Anomali Static Kitten February 2021)

  21. [21]
    Mango Sandstorm

    (Citation: Microsoft Threat Actor Naming July 2023)

  22. [22]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  23. [23]
    MuddyKrill

    (Citation: Cloudflare 2026 Threat Report New Threat Actors March 2026)

  24. [24]
    MuddyWater

    (Citation: Unit 42 MuddyWater Nov 2017)(Citation: Symantec MuddyWater Dec 2018)

  25. [25]
    Seedworm

    (Citation: Symantec MuddyWater Dec 2018)(Citation: Anomali Static Kitten February 2021)(Citation: Trend Micro Muddy Water March 2021)

  26. [26]
    Static Kitten

    (Citation: Anomali Static Kitten February 2021)(Citation: Trend Micro Muddy Water March 2021)

  27. [27]
    TA450

    (Citation: Proofpoint TA450 Phishing March 2024)

  28. [28]
    TEMP.Zagros

    (Citation: FireEye MuddyWater Mar 2018)(Citation: Anomali Static Kitten February 2021)(Citation: Trend Micro Muddy Water March 2021)

  29. [29]
    mitre-attackG0069
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.