MuddyC3 is a malware/tool associated with the espionage-focused threat group COBALT ULSTER, also known as MuddyWater, Seedworm, MERCURY, Mango Sandstorm, TA450, and other aliases. CTU researchers assess with moderate confidence that COBALT ULSTER operates on behalf of Iran and has conducted operations since at least 2017. The group has targeted government, telecommunications, oil and gas, and education organizations across the Middle East, Central Asia, and North America, including NGOs and Middle Eastern governments in late 2019 and early 2020. MuddyC3 appears in reporting as part of the group’s broader tooling ecosystem alongside PowerStats, FORELORD, Mori, PowGoop, Small Sieve, Canopy, PhonyC2, MuddyC2Go, Venom Proxy, and numerous publicly available offensive tools such as Metasploit, LaZagne, Koadic, CrackMapExec, Empire, Mimikatz, Plink, WMIExec, Ligolo, and Revsocks. The group commonly uses macro-enabled phishing documents for initial access, leverages compromised infrastructure for command and control, and has inserted false flags into code to complicate attribution and analysis. The provided content does not describe MuddyC3’s specific technical capabilities, infection chain, or indicators of compromise beyond its association with COBALT ULSTER and its inclusion in that actor’s toolset.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ToolsPowerStats, Koadic, LaZagne, Metasploit, FORELORD, CrackMapExec, Plink, Empire, Mimikatz, Mori, PowGoop, Small Sieve, Canopy, ScreenConnect, RemoteUtilities, Syncro, SimpleHelp, MiniDump, CredNinja, MKL64, Ligolo, MuddyC3, PhonyC2, MuddyC2Go, Venom Proxy, WMIExec, AnyDesk, Revsocks
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.