Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇮🇷 IR3 malware families

Muddy Water

Also known asmuddy_water

MuddyWater is an Iran-nexus APT assessed in the provided content as subordinate to Iran’s Ministry of Intelligence and Security (MOIS), active since at least 2017. Aliases explicitly mentioned in the content include Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, and TA450. The group is described as conducting espionage-oriented and other Iran-linked operations, and was identified by the Israel National Cyber Directorate among Iranian groups behind at least 15 phishing campaigns targeting Israeli public- and private-sector organizations. INCD stated these campaigns used tailored social-engineering lures such as fake Rafael job offers on LinkedIn, spoofed security-update emails, cash-offer scams, and academic conference invitations with malicious links, with the objective of gaining initial access and then moving deeper into victim organizations for espionage, damage, information gathering, and influence operations. The content also attributes to MuddyWater a spearphishing campaign targeting diplomatic, maritime, financial, telecommunications, and other sectors across the Middle East. In that activity, malicious Microsoft Word documents with VBA macros and icon spoofing were used to deliver a Rust-based implant referred to as RustyWater, aligned in the reporting with Archer RAT / RUSTRIC. The macros decoded a hex-embedded payload, wrote it to C:\ProgramData\CertificationKit.ini, and executed it via an obfuscated WScript.Shell/cmd.exe chain. Reported RustyWater capabilities include anti-debugging and anti-tampering via a vectored exception handler, host-information collection, string obfuscation with XOR, discovery of more than 25 antivirus/EDR products, persistence via a Windows Run registry key, asynchronous HTTP command-and-control using Rust reqwest and tokio, JSON/Base64/XOR multilayer data obfuscation for exfiltration, randomized jitter, and process injection into explorer.exe using VirtualAllocEx and WriteProcessMemory. The reporting characterizes this as an evolution from MuddyWater’s legacy PowerShell/VBS-heavy tradecraft toward a more modular, lower-noise Rust RAT.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Academia & Research
  • Software & Services

Where they target

Geographies tied to known operations.

  • 🇮🇱 Israel

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics3 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
IOCS

Observables

3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping3

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables3

Domains, IPs, and hashes tied to this actor, refreshed continuously.