Security researchers and government analysts said the Iranian state-linked MuddyWater group continued broad cyberespionage operations across the Middle East and nearby regions while evolving its malware and command-and-control infrastructure. Recent reporting tied the actor to a previously unreported Go-based C2 framework, MuddyC2Go, which appears to have replaced older PhonyC2 infrastructure after source code leaks and has been active since at least 2020. Campaigns linked to the framework targeted a Jordanian company, an Iraqi telecommunications provider, and likely Israeli organizations, while earlier activity hit government, telecom, and intergovernmental entities in Turkey, Jordan, Iraq, Georgia, Azerbaijan, Armenia, Pakistan, and other regional states through spearphishing, malicious archives, macro-enabled Office files, PDFs, and PowerShell-heavy loaders.
Across multiple campaigns, MuddyWater used a shifting toolset that included POWGOOP, Canopy/Starwhale, Mori, ForeLord, POWERSTATS, Covicli, lightweight VBS first-stage malware, DNS-tunneling RATs, ASP.NET web shells, and tunneling utilities such as SSF and Ligolo. Analysts also linked the group to exploitation of CVE-2020-0688 and possible use of CVE-2020-1472 in operations against Israeli targets, including an intrusion assessed as potentially destructive through deployment of PowGoop and a Thanos-based wiper-like payload disguised as ransomware. Despite changes in malware families and infrastructure, reports consistently described the actor as relying heavily on PowerShell, credential theft, persistence via registry keys or scheduled tasks, and rapidly changing C2 servers, underscoring a sustained Iranian espionage capability with occasional escalation toward disruptive effects.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
On November 8, 2023, Deep Instinct published research on a previously unreported Go-based command-and-control framework it named MuddyC2Go and attributed to MuddyWater. The report said the group appeared to have shifted from PhonyC2 to MuddyC2Go and linked historical and recent infrastructure across multiple campaigns.
On October 11, 2023, Deep Instinct identified a VirusTotal scan from Israel of a unique MuddyC2Go URL that returned PowerShell. The company assessed the scan likely indicated a recent MuddyWater attack against an Israeli target using C2 IP 94.131.109[.]65.
In September 2023, Deep Instinct identified additional PowerGUI-built executables distributed in password-protected RAR archives uploaded from Iraq. The activity was linked to attacks against Korek, an Iraqi-Kurdish telecommunications provider, using the hostname ghostrider.serveirc[.]com.
In July 2023, Deep Instinct identified an executable named offtec.exe in an attack against a Jordanian company. The PowerGUI-built sample executed embedded PowerShell that connected to MuddyC2Go server 45.150.64[.]239 before switching to microsoftfice.ddns[.]net.
Deep Instinct said IP address 141.95.177[.]130 hosted MuddyC2Go in April 2022 and resolved via passive DNS to jbf1.nc1310022a[.]biz. The naming pattern matched one previously seen with PhonyC2 servers.
Deep Instinct linked IP address 164.132.237[.]65, previously included by CISA as a MuddyWater indicator, to MuddyC2Go activity observed in March 2022. This connected the newer Go-based C2 framework to already attributed MuddyWater infrastructure.
On February 24, 2022, CISA, the FBI, NSA, NCSC-UK, and U.S. Cyber Command CNMF released a malware analysis report covering 23 MuddyWater-attributed files. The report detailed POWGOOP, JavaScript PowerShell beacons, the Mori backdoor, and Canopy/Starwhale Excel lures.
On January 31, 2022, Cisco Talos published findings on MuddyWater campaigns targeting Turkish users with malicious PDFs and executables. The reporting tied the activity to the Iranian APT and its use of phishing and malware delivery chains.
Cisco Talos said MuddyWater attempted two campaigns against Turkey in November 2021. Talos linked the activity to the group's broader use of phishing, PowerShell-based tooling, and SloughRAT-related tradecraft.
Cisco Talos reported that MuddyWater targeted Armenia in June 2021 using Windows executable files similar to those seen in other campaigns. Talos presented this as part of broader 2021 regional activity by the group.
Cisco Talos observed a MuddyWater attack against Pakistan in April 2021. One delivery chain used a PowerShell-based downloader that accepted PS1 commands from C2, while another used a malicious court-themed document.
ClearSky reported that during September 2020 it identified Operation Quicksand, a MuddyWater-attributed campaign targeting many prominent Israeli organizations. The operation used malicious documents and exploitation of Microsoft Exchange CVE-2020-0688, and ClearSky assessed it as MuddyWater's first known potentially destructive campaign.
Lab52 said a MuddyWater campaign using compressed archives, malicious Word documents, VBA macros, and a lightweight VBS RAT had been active since the last quarter of 2020. Researchers collected samples dated from November 2020 through January 2022 targeting countries across the Middle East and nearby regions.
Secureworks reported that Iranian state-linked MuddyWater activity continued through mid-January 2020 with spearphishing campaigns and a previously unobserved RAT dubbed ForeLord. The firm said it had not observed government-directed cyber retaliation tied to regional tensions as of its reporting.
Deep Instinct said IP address 109.201.140[.]103 showed unique MuddyC2Go URLs in scans from January 2020, including one from Egypt. The company assessed MuddyWater may have been using the Go-based framework since at least 2020.
In April 2019, Telegram leaks exposed alleged MuddyWater C2 backends, source code, and victim lists. Trend Micro assessed the leaked material was likely based on real MuddyWater operational data after comparing it with independently observed backend code and victim communications.
Trend Micro reported that first-half 2019 MuddyWater campaigns used compromised email accounts and a new multi-stage PowerShell backdoor called POWERSTATS v3. The infection chain used malicious macros, encoded VBE files, and staged PowerShell payloads disguised with image-like extensions.
Secureworks observed espionage-focused spearphishing campaigns by COBALT ULSTER/MuddyWater between mid-2019 and mid-January 2020 targeting government organizations in Turkey, Jordan, and Iraq, as well as entities in Georgia and Azerbaijan. Trend Micro also attributed first-half 2019 campaigns against a Jordanian university and the Turkish government to MuddyWater.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
deepinstinct.com
Open sourcelab52.io
Open sourcetechrepublic.com
Open sourcecisa.gov
Open sourceblog.talosintelligence.com
Open sourcesecureworks.com
Open sourcedocuments.trendmicro.com
Open sourceclearskysec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.