Iran-linked espionage group Seedworm—also tracked as MuddyWater—was reported targeting government, telecommunications, and private-sector organizations across the Middle East and later telecom providers in North and East Africa. Symantec said the group pursued data theft in countries including Iraq, Kuwait, Turkey, the UAE, Egypt, Sudan, and Tanzania, while additional reporting tied earlier activity to Turkey, Afghanistan, Iraq, Azerbaijan, and Iran. Victim sectors included government, telecoms, technology, oil and gas, education, and real estate, with some intrusions showing signs of persistent access over extended periods.
Researchers said Seedworm continued to rely on phishing, credential dumping, PowerShell, and DLL side-loading while rotating through a mix of custom and publicly available tools. Observed malware and utilities included Backdoor.Mori, PowGoop, MuddyC2Go, POWERSTATS, SSF, Chisel, SimpleHelp, Venom Proxy, Revsocks, AnyDesk, and a custom keylogger; in one case, MuddyC2Go was sideloaded through the legitimate jabswitch.exe Java binary. Group-IB also reported leaks exposing screenshots, command-and-control servers, victim IPs, and malware linked to MuddyWater operations, indicating the Iranian state-linked actor suffered an operational compromise but later resumed espionage activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Deep Instinct first publicly documented the MuddyC2Go backdoor on November 8, 2023. Researchers assessed that the malware may have been used by Seedworm since 2020 and may have replaced the group's earlier PhonyC2 infrastructure after a 2023 source-code leak.
Symantec observed a Seedworm cyberespionage campaign in November 2023 targeting telecommunications organizations in Egypt, Sudan, and Tanzania. The activity used MuddyC2Go, SimpleHelp, Venom Proxy, Revsocks, AnyDesk, PowerShell, and a custom keylogger, with evidence that one victim had been infiltrated earlier in 2023.
Symantec disclosed a likely Iran-linked espionage campaign targeting telecom operators, several IT services organizations, and a utility company across Israel, Jordan, Kuwait, Saudi Arabia, the UAE, Pakistan, Thailand, and Laos over a six-month period in 2021. The intrusions relied on legitimate remote administration tools, public offensive tools, credential theft, lateral movement, and Exchange server web shells, with possible links to Seedworm based on overlapping infrastructure and tool versions.
Trend Micro published research on March 5, 2021, stating that MuddyWater (tracked by Trend Micro as Earth Vetala) continued targeting organizations in the Middle East. The report publicly documented the group's ongoing regional activity as a separate disclosure from later 2021 reporting.
Symantec said Seedworm activity in one compromised organization continued until at least July 2020. The intrusion involved credential theft, registry hive dumping, Quarks PwDump, and tunneling tools including SSF and Chisel.
Symantec noted that the PowGoop loader was first publicly reported in July 2020. The tool was later observed overlapping with Seedworm activity, though Symantec assessed that link with medium confidence.
In one victim organization later analyzed by Symantec, Seedworm dropped and installed Backdoor.Mori on a SQL server as early as December 2019. This marked an early confirmed foothold in the intrusion set described in Symantec's investigation.
Group-IB discovered a leak of ASELSAN A.Ş email addresses in April 2019 while investigating MuddyWater activity. The researchers later correlated public leaks and found about 400 unique credentials tied to the @aselsan.com.tr domain.
Group-IB reported that MuddyWater ran phishing and espionage operations from February to April 2019 against government, educational, financial, telecommunications, and defense entities in Turkey, Iran, Afghanistan, Iraq, and Azerbaijan. The campaign used POWERSTATS and themed lure documents, including material aimed at Turkish defense contractor ASELSAN A.Ş.
Group-IB said unknown individuals published leaks during the spring that exposed tools, victims, and links associated with Iranian government-affiliated APT groups including OilRig and MuddyWater. Information on MuddyWater later appeared on the dark web and Telegram as dumps, source-code screenshots, C2 server details, and victim IP addresses, with Green Leakers claiming responsibility.
Symantec disclosed a recent wave of Seedworm espionage activity targeting government and private-sector organizations across the Middle East and nearby regions. The campaign affected countries including Iraq, Turkey, Kuwait, the UAE, Georgia, Afghanistan, Israel, Azerbaijan, Cambodia, and Vietnam, and included overlap with PowGoop infections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
group-ib.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcetrendmicro.com
Open sourcecyberscoop.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.