MuddyWater is an Iranian state-linked cyber espionage threat actor widely associated with Iran’s Ministry of Intelligence and Security (MOIS). It is tracked under numerous aliases including Seedworm, Static Kitten, MERCURY, Mango Sandstorm, Boggy Serpens, TA450, TEMP.Zagros, Earth Vetala, Yellow Nix, ITG17, and G0069. The group has been active since at least 2017 and is known for long-running intelligence collection, access development, and strategic pre-positioning operations rather than primarily destructive or financially motivated activity. MuddyWater has targeted government, defense, telecommunications, energy, financial, nonprofit, transportation, aerospace, and technology organizations across the Middle East, Israel, Iraq, Europe, and North America, including the United States and Canada. Reporting in 2026 linked the group to intrusions affecting a U.S. financial institution, a U.S. airport, nonprofits, and the Israeli operation of a U.S. software supplier serving defense and aerospace customers. The actor’s operational pattern is consistent with espionage and persistence-building intended to preserve future options for intelligence collection, coercion, selective disruption, or downstream access. The group is known for pragmatic tradecraft that blends custom malware with commodity tooling and legitimate services. MuddyWater has historically relied on spearphishing, including malicious Office documents and macro-enabled lures, compromised mailboxes, and more recent social-engineering approaches using collaboration platforms and recruitment-themed impersonation. It frequently abuses PowerShell and other scripting environments, DLL sideloading, remote management and monitoring tools, cloud storage, and trusted web services to reduce signature-based detection opportunities. Observed persistence mechanisms include Registry Run keys and Startup-related autostart methods. Malware and tooling associated with MuddyWater include Dindoor, Fakeset, PowGoop, Small Sieve, Mori, POWERSTATS, Canopy or Starwhale, MuddyViper, GhostBackDoor, Stagecomp, Darkcomp, CHAR, GhostFetch, HTTP_VIP, RustyWater, and ZionSiphon. Recent reporting also described use of Deno-based and Python-based implants, Rust-based payloads, Telegram-backed command channels, reflective loading, cloud-based exfiltration, and attempts to blend command-and-control and staging into legitimate enterprise traffic. The group has also been linked to use of commodity and criminal-ecosystem tooling, including remote administration software and malware-as-a-service components such as CastleRAT and ChainShell. In some cases, MuddyWater activity has reportedly leveraged ransomware or ransomware-branded operations, including Chaos, as cover for espionage objectives. Operationally, MuddyWater commonly employs spearphishing attachment and link delivery, user execution, command and scripting interpreters, ingress tool transfer, valid accounts, exfiltration over web services, and application-layer command-and-control. The actor has also demonstrated low-signature tradecraft through use of legitimate cloud platforms, commercial storage providers, and dual-use administration tools, reflecting a broader shift toward behaviorally stealthy operations that minimize reliance on easily blocked attacker-controlled infrastructure. MuddyWater is best understood as a persistent MOIS-aligned espionage and access-enablement actor within the broader Iranian cyber ecosystem. Public reporting also notes technical or operational overlaps between MuddyWater and other Iran-nexus clusters, including Lyceum and Cavern Manticore, though such overlaps do not always establish direct equivalence. Its campaigns consistently emphasize durable footholds, credential access, internal reconnaissance, and covert data theft in support of Iranian strategic intelligence requirements.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
51 malware families attributed to this actor across reporting.
46 additional families tracked in Mallory.
34 CVEs this actor has used in observed campaigns. 34 of them exploited in the wild.
MuddyWater has been observed conducting a broad reconnaissance campaign across more than 12,000 internet-exposed systems by exploiting known security flaws in internet-exposed ... Langflow ... systems. The list of exploited vulnerabilities is as follows - CVE-2025-34291 - Langflow remote code execution vulnerability
CVEs Weaponized by This Cluster CVE-2025-54068 — Laravel Livewire v3 RCE
CVE-2017-0199 - уязвимость Microsoft Office, позволяющая удалённое выполнение кода через специально сформированный документ (CVSS 7.8, HIGH, вектор AV:L/AC:L/PR:N/UI:R - требуется действие пользователя), внесена в CISA KEV как активно эксплуатируемая и связанная с ransomware. Ряд публикаций связывает эксплуатацию CVE-2017-0199 с MuddyWater, однако атрибуция требует подтверждения по MITRE ATT&CK G0069.
The attackers attempt to exploit Exchange servers using two different tools: A publicly available script for exploiting CVE-2020-0688 (T1190) Ruler – an open source Exchange exploitation framework
FBI, CISA, CNMF, and NCSC-UK have observed this APT group recently exploiting the Microsoft Netlogon elevation of privilege vulnerability (CVE-2020-1472) and the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688).
29 more CVEs tied to this actor tracked in Mallory.
618 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked actor deploying RustyWater and ZionSiphon against targets in Israel and Iraq.
Referenced as an Iranian state-backed group that leveraged Chaos to mask espionage activity as financially motivated ransomware operations.
Conducting intrusions for long-term access, including abuse of signed software, deployment of multiple backdoors, and attempted data transfer to commercial cloud storage against organizations in the U.S. and Israel.
Referenced as an overlapping or related Iran-linked threat actor in connection with Cavern Manticore; no direct attribution by Group-IB.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.