MuddyWater is an Iranian state-sponsored threat actor assessed to operate on behalf of the Ministry of Intelligence and Security (MOIS). It is widely tracked under aliases including Seedworm, Static Kitten, TEMP.Zagros, TA450, Mango Sandstorm, Mercury, Boggy Serpens, Earth Vetala, Cobalt Ulster, and Yellow Nix. The group conducts cyber espionage and related malicious cyber operations against government and private-sector organizations across the Middle East, Asia, Africa, Europe, and North America. MuddyWater has targeted sectors including government, telecommunications, defense, and oil and natural gas, with reporting also indicating campaigns focused primarily on the Middle East and activity against Turkey and other Asian countries. The actor is known for spearphishing, including use of compromised third parties and compromised accounts to send targeted emails with malicious attachments. It has also abused legitimate remote monitoring and management tools such as Syncro, AteraAgent, Remote Utilities, ConnectWise, and SimpleHelp to support intrusion activity. Operationally, MuddyWater frequently relies on PowerShell for execution and has used mshta.exe to launch payloads such as POWERSTATS and to pass PowerShell one-liners. The group has established persistence through scheduled tasks and has used publicly available malware and tooling, likely in part to blend with broader criminal activity and complicate attribution. It has also used the .NET csc.exe compiler to build executables from downloaded C# source code after delivery. Post-compromise behavior associated with MuddyWater includes process discovery, collection of system and user information, screenshot capture, browser credential theft, and transfer of additional files to victim systems. Reported capabilities include obtaining lists of running processes, collecting operating system version, machine name, and username data, stealing passwords saved in web browsers through tools such as Browser64, and encoding command-and-control communications with Base64. Reporting also notes overlaps between MuddyWater and other Iranian intrusion activity, including Cavern Manticore and an OilRig sub-group known as Lyceum.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
58 malware families attributed to this actor across reporting.
53 additional families tracked in Mallory.
34 CVEs this actor has used in observed campaigns. 34 of them exploited in the wild.
The government agencies recently observed MuddyWater exploiting the Microsoft Netlogon elevation of privilege vulnerability CVE-2020-1472 and the Microsoft Exchange memory corruption vulnerability CVE-2020-0688.
MuddyWater has been observed conducting a broad reconnaissance campaign across more than 12,000 internet-exposed systems by exploiting known security flaws in internet-exposed ... Langflow ... systems. The list of exploited vulnerabilities is as follows - CVE-2025-34291 - Langflow remote code execution vulnerability
Clearsky has detected new and advanced attack vector used by MuddyWater to target governmental entities and the telecommunication sector. Notably, the TTP includes decoy documents exploiting CVE-2017-0199 as the first stage of the attack... Attack Vector 2 – CVE-2017-0199 ... MuddyWater has not used this TTP previously.
CVEs Weaponized by This Cluster CVE-2025-54068 — Laravel Livewire v3 RCE
Recently, Microsoft revealed that MuddyWater had been leveraging the ZeroLogon vulnerability as well (CVE-2020-1472)... CVE-2020-1472 - An elevation of privilege vulnerability that exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC).
29 more CVEs tied to this actor tracked in Mallory.
1,096 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an overlapping Iranian threat actor associated by tradecraft or organizational overlap with Cavern Manticore.
Conducting espionage and intellectual property theft campaigns, and also associated with deploying ransomware and destructive malware, primarily via malicious documents that deliver RATs against government, university, and telecommunications targets.
Iranian government-linked cyberespionage actor targeting telecommunications, defense, local government, and oil and natural gas organizations, using spear-phishing, open-source tools, persistence mechanisms, and multiple backdoors/loaders; also observed deploying ransomware and exploiting known vulnerabilities.
Iran-linked state-sponsored espionage actor that used Chaos ransomware branding as cover for credential harvesting, persistence, data exfiltration, account takeover, and extortion-style activity without deploying encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.