MuddyWater is an Iranian cyber threat actor known for targeting governments via spearphishing.
Analyst brief
MuddyWater is an Iranian nation-state cyber threat actor primarily targeting government entities in the Middle East (Saudi Arabia, Iraq, Israel, UAE) and neighboring regions (Turkey, Georgia, Pakistan), with additional activity in India and the USA. The group relies on spearphishing attachments and links for initial access, establishes persistence via Office Template Macros and Registry Run Keys, and uses tools like Mimikatz and LaZagne for credential access. Defenders should focus on strengthening email security, restricting PowerShell execution, monitoring for C2 traffic on non-standard ports, and detecting abuse of legitimate tools such as Rclone for exfiltration to cloud storage.
MuddyWater
TEMP.ZagrosStatic KittenSeedworm
nation-state
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.
origin (suspected)
🇮🇷Iran· state-sponsoredattribution confidence: medium (50)