MuddyViper is a Windows backdoor associated with the Iran-aligned MuddyWater espionage cluster, also tracked as Mango Sandstorm, TA450, Seedworm, and Static Kitten, and linked to Iran’s Ministry of Intelligence and Security. It emerged in campaigns active from late 2024 into 2025 that primarily targeted organizations in Israel, with at least one confirmed victim in Egypt, including entities in technology, engineering, manufacturing, local government, education, telecommunications, government, and energy-related sectors. The malware has also been assessed in some intrusions as supporting initial-access brokering for other Iran-aligned operations, including overlap with Lyceum.
MuddyViper is deployed by a custom loader known as Fooder, which reflectively loads the implant into memory and executes it in a largely memory-resident manner. Fooder has been disguised as a Snake-themed application and uses delayed execution logic to hinder automated analysis. Initial access in the observed campaigns was typically achieved through spearphishing emails carrying PDF lures that directed victims to installers for legitimate remote monitoring and management tools hosted on file-sharing services. Operators then used their foothold to deploy MuddyViper and related post-compromise tooling.
The backdoor provides broad control over compromised systems. Reported capabilities include collecting system information, executing arbitrary files and shell commands, transferring files, establishing reverse-shell-style access, stealing Windows login credentials and browser data, and exfiltrating stolen information. MuddyViper has also been described as checking for selected security tools in the victim environment, indicating defensive awareness and evasion-oriented tradecraft. Persistence has been observed through startup execution and scheduled-task mechanisms. Campaign reporting also notes use of Windows CNG cryptographic APIs, reduced hands-on-keyboard activity, and complementary credential-stealing components, all consistent with MuddyWater’s gradual shift toward more tailored and lower-noise intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Previous campaigns have employed malware families such as PowGoop, Small Sieve, Mori, POWERSTATS, Canopy/Starwhale, and more recently MuddyViper and GhostBackDoor variants.
Implant: MuddyViper reflectively loaded into memory Objective: Credential harvesting, network mapping, initial-access brokering for Lyceum
44 distinct techniques documented for this family, organized by ATT&CK tactic.
MuddyWater TTPs list includes “Execution T1047 Windows Management Instrumentation.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The group's WMI-based persistence and memory-resident implant execution are specifically designed to evade the host-based detection tools most commonly deployed in government environments.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.
MuddyWater TTPs list includes “Persistence T1137.001 Office Application Startup: Office Template Macros.”
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or batch files in the Windows Startup folder.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or batch files in the Windows Startup folder.
Black Shrantac TTPs list includes “Defense Evasion T1027 Obfuscated Files or Information.” MuddyWater TTPs list includes multiple T1027 sub-techniques (command obfuscation, steganography, compile after delivery).
Bisonal has deleted Registry keys to clean up its prior activity. FIN8 has deleted Registry keys during post compromise cleanup activities. SUNBURST also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
MuddyWater TTPs list includes “Defense Evasion T1140 Deobfuscate/Decode Files or Information.”
CastleRAT TTPs list includes “Defense Evasion T1218.011… Rundll32.” MuddyWater also lists “T1218.011… Rundll32.”
MuddyWater TTPs list includes “Discovery T1016 System Network Configuration Discovery.”
MuddyWater TTPs list includes “Discovery T1033 System Owner/User Discovery.”
MuddyWater TTPs list includes “Discovery T1049 System Network Connections Discovery.”
Black Shrantac TTPs list includes “Discovery T1057 Process Discovery.” MuddyWater TTPs list includes “Discovery T1057 Process Discovery.”
Black Shrantac TTPs list includes “Discovery T1082 System Information Discovery.” CastleRAT describes collecting “system metadata” and lists “Discovery T1082.” MuddyWater lists “Discovery T1082.”
Black Shrantac TTPs list includes “Discovery T1083 File and Directory Discovery.” MuddyWater TTPs list includes “Discovery T1083 File and Directory Discovery.”
MuddyWater TTPs list includes “Collection T1074.001 Data Staged: Local Data Staging.”
The content repeatedly describes threat actors, malware, and campaigns using HTTP, HTTPS, HTTP GET/POST, cookies in headers, WebSockets/WSS, and web APIs for command and control or related communications.
MuddyWater TTPs list includes “Command and Control T1102.002 Web Service: Bidirectional Communication.”
MuddyWater TTPs list includes “Command and Control T1104 Multi-Stage Channels.”
CastleRAT TTPs list includes “Command and control T1105 Ingress Tool Transfer.” MuddyWater also lists T1105.
MuddyWater TTPs list includes “Command and Control T1132.001 Data Encoding: Standard Encoding.”
The impact tier is the most varied; Shamoon 4.0, Meteor, BibiWiper, and MuddyViper represent the confirmed destructive payload suite. IOCONTROL directly targets IoT and fuel management OT systems. BaqiyatLock and Sicarii deploy pseudo-ransomware designed to destroy data rather than hold it for ransom.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive payload included in the confirmed active suite during the conflict.
Previously used MuddyWater malware family mentioned as historical background.
A memory-resident implant used for credential harvesting, network mapping, and initial-access brokering.
Custom MuddyWater backdoor reflecting the group’s move toward more tailored malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.