Boggy Serpens—also tracked as MuddyWater and linked to Iran’s Ministry of Intelligence and Security—has expanded a long-running cyberespionage effort targeting diplomatic entities and critical sectors including energy, maritime, aviation, and finance. Reporting indicates the group has shifted from broad, noisy spear-phishing and remote management tool abuse toward more deliberate operations focused on long-term persistence, trusted relationship compromise, and custom Rust-based malware, with activity observed across the Middle East, Europe, and South America. One cited campaign involved multiple attack waves against a UAE-based target, and researchers also noted coordination with Evasive Serpens/Lyceum, suggesting resource sharing within the broader Iranian threat ecosystem.
Broader coverage in the cluster reinforces that Iranian cyber activity remains a live concern for defenders, particularly against critical infrastructure and enterprise environments, even where no single surge in activity has been confirmed. U.S. officials said they had not observed an overall uptick in Iran-linked cyber threats despite regional conflict, but noted ongoing response work tied to an attack attributed to the Iran-linked Handala group. Additional material on Iranian tradecraft highlights recurring use of password spraying, exploitation of known vulnerabilities, legitimate administrative tools, and persistence-focused intrusion methods, which aligns with the operational evolution described for Boggy Serpens. Generic articles on critical infrastructure risk and APT defense provide context, but separate reporting on SideWinder and ad-tech privacy abuses is unrelated to the same event.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported that Boggy Serpens, also known as MuddyWater, conducted a multi-wave espionage campaign from August 2025 through February 2026 targeting diplomatic, energy, maritime, government, aviation, and financial organizations across several countries. The report highlighted use of compromised email accounts, fake diplomatic invitations, custom Rust-based implants, and malware families including BugSleep, Nuso, and UDPGangster.
CISA Acting Director Nick Andersen said the U.S. government had not observed an increase in Iran-linked cyber threats since U.S. and Israeli strikes in Iran late the previous month. He said the agency was coordinating with industry and sector groups while urging defenders to remain vigilant.
Reporting described a recurring Iranian cyber operations model centered on password spraying, exploitation of known N-day vulnerabilities, and living-off-the-land techniques using tools such as PowerShell and RDP. The activity was associated with groups including Pioneer Kitten and Seedworm and was presented as an ongoing pattern rather than a single new incident.
Stryker suffered a cyberattack on March 11 that U.S. officials attributed to the Iran-linked group Handala. CISA later said it was still assisting the company in responding to the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetherecord.media
Open sourcecobalt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.