MuddyWater is an Iranian state-aligned cyber espionage threat actor widely assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least 2017, the group is known under numerous aliases including Seedworm, MERCURY, Static Kitten, Mango Sandstorm, TA450, TEMP.Zagros, Boggy Serpens, Cobalt Ulster, Earth Vetala, ITG17, and ATT&CK group G0069. Its operations are primarily intelligence-driven and focused on long-term access, pre-positioning, credential theft, reconnaissance, and data exfiltration rather than financially motivated crime, though it has also been linked to access-enablement activity preceding destructive operations by other Iranian actors. MuddyWater has targeted government, defense, energy, telecommunications, financial services, aviation, education, manufacturing, professional services, public-sector, and IT-provider organizations. Victim geography has centered on the Middle East, especially Israel and neighboring states, but the group has also targeted organizations in the United States, Canada, Europe, Asia, and other regions of strategic interest to Iran. Reported campaigns include spearphishing against diplomatic, telecom, maritime, energy, and enterprise targets; compromise of IT and service-provider relationships; and broad reconnaissance against internet-exposed enterprise applications. The actor is notable for flexible tradecraft and frequent use of legitimate tools and services to reduce detection. Across campaigns, MuddyWater has used malicious Office documents with VBA macros, external-template and HTML-based lures, PowerShell and script-based execution, DLL sideloading, remote monitoring and management software, cloud storage services, and trusted file-sharing or developer platforms. It has repeatedly abused legitimate remote access and administration tooling such as AnyDesk, ScreenConnect, Atera, Syncro, SimpleHelp, Action1, Level, PDQ, and similar software for persistence and post-compromise operations. Recent reporting also describes use of collaboration-platform social engineering, including Microsoft Teams impersonation of IT support personnel. Malware and tooling associated with MuddyWater include POWERSTATS, PowGoop, Small Sieve, Mori, Canopy or Starwhale, MuddyViper, GhostBackDoor, GhostFetch, HTTP_VIP, CHAR, Stagecomp, Darkcomp, Dindoor, and Fakeset, as well as use of commercial or criminal ecosystem tooling such as CastleRAT MaaS and ChainShell. Recent operations show a shift toward low-signature implants and dual-use runtimes, including Deno- and Python-based backdoors, Node.js-driven scripting, in-memory execution, and exfiltration through common cloud services. The group has also used browser data theft tooling and malware that enumerates security products, collects host metadata such as OS version and machine name, and performs Active Directory and cloud-administration reconnaissance. Common MuddyWater tactics, techniques, and procedures include spearphishing attachment and link delivery, user execution, command and scripting interpreter abuse, ingress tool transfer, registry-based persistence, startup persistence, credential harvesting, security software discovery, system information discovery, lateral movement using legitimate administrative channels, and exfiltration over web services. The group has demonstrated anti-analysis and evasion behaviors such as in-memory payload loading, obfuscated macros, hidden payload storage in document forms, sandbox-delay logic, use of signed or trusted binaries for sideloading, and blending command-and-control or exfiltration traffic into legitimate HTTPS, cloud, and messaging services. MuddyWater’s operational pattern reflects sustained espionage and strategic access development in support of Iranian intelligence priorities. In 2026 reporting, the group was linked to pre-positioning intrusions against organizations in the United States, Israel, and Canada; use of cloud-based exfiltration and trusted infrastructure; and access operations assessed to have enabled follow-on disruptive activity by other Iranian clusters. Technical and operational overlaps have also been noted with other Iranian MOIS-linked actors, including Lyceum, and the group remains one of the most prominent and persistent Iranian cyber espionage actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
55 malware families attributed to this actor across reporting.
50 additional families tracked in Mallory.
34 CVEs this actor has used in observed campaigns. 34 of them exploited in the wild.
MuddyWater has been observed conducting a broad reconnaissance campaign across more than 12,000 internet-exposed systems by exploiting known security flaws in internet-exposed ... Langflow ... systems. The list of exploited vulnerabilities is as follows - CVE-2025-34291 - Langflow remote code execution vulnerability
CVEs Weaponized by This Cluster CVE-2025-54068 — Laravel Livewire v3 RCE
CVE-2017-0199 - уязвимость Microsoft Office, позволяющая удалённое выполнение кода через специально сформированный документ (CVSS 7.8, HIGH, вектор AV:L/AC:L/PR:N/UI:R - требуется действие пользователя), внесена в CISA KEV как активно эксплуатируемая и связанная с ransomware. Ряд публикаций связывает эксплуатацию CVE-2017-0199 с MuddyWater, однако атрибуция требует подтверждения по MITRE ATT&CK G0069.
The attackers attempt to exploit Exchange servers using two different tools: A publicly available script for exploiting CVE-2020-0688 (T1190) Ruler – an open source Exchange exploitation framework
FBI, CISA, CNMF, and NCSC-UK have observed this APT group recently exploiting the Microsoft Netlogon elevation of privilege vulnerability (CVE-2020-1472) and the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688).
29 more CVEs tied to this actor tracked in Mallory.
612 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Leveraged criminal MaaS tooling to target defense, energy, government, and telecom organizations across Israel, the Middle East, the US, and Europe.
Iranian state-linked cyber espionage group conducting repeated spear-phishing waves against energy and maritime targets in the Middle East/MENA, using malicious Office documents, VBA macros, custom loaders/backdoors, Telegram Bot API and HTTP C2, and legitimate RMM tools such as AnyDesk for post-compromise access and data exfiltration.
Referenced as an Iran-linked threat actor with technical overlaps to Cavern Manticore.
Referenced as an Iranian threat group whose techniques and links overlap with Cavern Manticore, supporting attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.