Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇮🇷 IR5 malware families

MuddyCoast

Also known asmuddycoastunc3313

UNC3313, also referred to as MuddyCoast, is an Iran-nexus threat group. The provided content describes it as conducting surveillance and strategic information-gathering operations via spear-phishing campaigns, and as an Iranian group active against Israel and the Middle East. One cited report states UNC3313 is affiliated with MuddyWater. Reported activity includes distribution of the JELLYBEAN dropper and CANDYBOX backdoor using phishing lures and file-sharing services, and use of up to nine legitimate remote monitoring and management tools to evade detection and maintain access. Mandiant also attributed multiple backdoors to UNC3313, including STARWHALE, STARWHALE.GO, and GRAMDOOR. STARWHALE is a VBScript/WSF backdoor that establishes persistence by creating a Windows service, performs host enumeration, communicates with a hardcoded C2 over HTTP POST using custom encoding, and executes commands via cmd.exe. STARWHALE.GO is a Golang variant delivered via certutil and an NSIS installer, persists via a Run key, exchanges JSON over HTTP POST with a hardcoded C2, and executes received commands via cmd.exe or directly based on file extension. GRAMDOOR is a Python 3.9 / PyInstaller backdoor delivered via an NSIS installer, persists via a Windows Run key, only executes on Windows 8 and higher, and uses the Telegram Bot API for command-and-control. Additional observed tradecraft includes storing PowerShell downloader commands in Registry keys referenced by a scheduled task, and downloading and installing the legitimate eHorus remote access tool as a Windows service for remote access. Google also reported that Iranian hackers MuddyCoast (UNC3313) used Gemini for malware development and debugging, accidentally exposing C2 domains and keys. Known aliases in the provided content are MuddyCoast and UNC3313.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics44 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.006
Web Services
TA0001
Initial Access
2 techniques
T1190×2
Exploit Public-Facing Application
T1566×2
Phishing
T1566.001×3
Spearphishing Attachment
TA0002
Execution
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059×2
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003×2
Windows Command Shell
T1204
User Execution
T1204.002×3
Malicious File
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1543
Create or Modify System Process
T1543.003
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1497
Virtualization/Sandbox Evasion
T1620
Reflective Code Loading
TA0006
Credential Access
3 techniques
T1003
OS Credential Dumping
T1539
Steal Web Session Cookie
T1555
Credentials from Password Stores
TA0007
Discovery
2 techniques
T1082×3
System Information Discovery
T1497
Virtualization/Sandbox Evasion
TA0008
Lateral Movement
1 technique
T1021×3
Remote Services
TA0009
Collection
1 technique
T1115
Clipboard Data
TA0011
Command and Control
5 techniques
T1071×2
Application Layer Protocol
T1071.001×2
Web Protocols
T1090×2
Proxy
T1090.003
Multi-hop Proxy
T1102
Web Service
T1102.002
Bidirectional Communication
T1105×3
Ingress Tool Transfer
T1219×2
Remote Access Tools
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping29

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.