MuddyWater is an Iranian state-aligned cyber espionage threat actor widely assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least 2017, the group is best known for long-running intelligence collection and pre-positioning operations against government, defense, telecommunications, energy, financial, aviation, public-sector, education, and IT-service targets across the Middle East, Israel, the United States, Europe, and other regions. Common aliases include Seedworm, MERCURY, Static Kitten, Mango Sandstorm, Boggy Serpens, TA450, Temp.Zagros, Earth Vetala, Yellow Nix, Cobalt Ulster, and ITG17. The group’s operations consistently emphasize espionage, credential theft, network mapping, and durable access rather than overt disruption, although its intrusions have also been described as enabling later destructive or strategic effects. MuddyWater frequently conducts repeated spearphishing waves tailored to specific departments or individuals, often using malicious Office documents, VBA macros, external template abuse, HTML lures, and social engineering themes tied to business, travel, government, or technical support. More recent activity also shows adoption of collaboration-platform phishing and ClickFix-style user-execution lures. MuddyWater is notable for pragmatic tradecraft that blends custom malware, commodity tooling, living-off-the-land techniques, and legitimate remote management software. Reported malware and tooling associated with the actor include Dindoor, Fakeset, GhostFetch, GhostBackDoor, CHAR, HTTP_VIP, PowGoop, Small Sieve, Mori, POWERSTATS, Canopy or Starwhale, MuddyViper, Stagecomp, Darkcomp, and RustyWater. The group has also abused legitimate or dual-use tools and services such as AnyDesk, ScreenConnect, Atera, SimpleHelp, Action1, Level, PDQ, Syncro, Remote Utilities, Node.js, Deno, Rclone, Telegram, and cloud storage or file-sharing platforms to reduce signature-based visibility and blend malicious traffic with normal enterprise activity. Observed techniques include spearphishing attachment delivery, user execution, command and scripting interpreter abuse, DLL sideloading, reflective loading, ingress tool transfer, registry-based persistence, startup persistence, security software discovery, system information discovery, credential harvesting, Active Directory reconnaissance, cloud and identity enumeration, exfiltration over web services, and application-layer command and control. MuddyWater malware has been reported to check for security tools, collect host metadata such as operating system version and machine name, and use anti-analysis measures including obfuscated macros and sandbox-delay logic. The actor has also increasingly relied on trusted cloud services and low-signature infrastructure, reflecting a shift toward behaviorally stealthy operations rather than easily blocked indicator-heavy tradecraft. Recent reporting links MuddyWater to campaigns using Rust-based implants, Deno- and Python-based backdoors, Telegram-backed command channels, and malware-as-a-service or criminal ecosystem tooling such as CastleRAT MaaS and ChainShell. Victimology in 2025–2026 includes organizations in Israel, the broader Middle East, the United States, Canada, Europe, and Asia, with targeting spanning defense, energy, government, telecommunications, manufacturing, aviation, financial services, and software supply-chain-adjacent entities. The group’s operational pattern, infrastructure overlaps, and sustained use of social engineering and legitimate administration tooling make it a persistent Iranian espionage actor of high strategic relevance.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
48 malware families attributed to this actor across reporting.
43 additional families tracked in Mallory.
34 CVEs this actor has used in observed campaigns. 34 of them exploited in the wild.
MuddyWater has been observed conducting a broad reconnaissance campaign across more than 12,000 internet-exposed systems by exploiting known security flaws in internet-exposed ... Langflow ... systems. The list of exploited vulnerabilities is as follows - CVE-2025-34291 - Langflow remote code execution vulnerability
CVEs Weaponized by This Cluster CVE-2025-54068 — Laravel Livewire v3 RCE
CVE-2017-0199 - уязвимость Microsoft Office, позволяющая удалённое выполнение кода через специально сформированный документ (CVSS 7.8, HIGH, вектор AV:L/AC:L/PR:N/UI:R - требуется действие пользователя), внесена в CISA KEV как активно эксплуатируемая и связанная с ransomware. Ряд публикаций связывает эксплуатацию CVE-2017-0199 с MuddyWater, однако атрибуция требует подтверждения по MITRE ATT&CK G0069.
The attackers attempt to exploit Exchange servers using two different tools: A publicly available script for exploiting CVE-2020-0688 (T1190) Ruler – an open source Exchange exploitation framework
FBI, CISA, CNMF, and NCSC-UK have observed this APT group recently exploiting the Microsoft Netlogon elevation of privilege vulnerability (CVE-2020-1472) and the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688).
29 more CVEs tied to this actor tracked in Mallory.
614 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian APT using malicious Office macros and commodity tools; associated here with Operation Olalampo.
Referenced as one of several state-backed groups incorporating ClickFix into existing infection chains.
Leveraged criminal MaaS tooling to target defense, energy, government, and telecom organizations across Israel, the Middle East, the US, and Europe.
Iranian state-linked cyber espionage group conducting repeated spear-phishing waves against energy and maritime targets in the Middle East/MENA, using malicious Office documents, VBA macros, custom loaders/backdoors, Telegram Bot API and HTTP C2, and legitimate RMM tools such as AnyDesk for post-compromise access and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.