Muddy Water
MuddyWater is an Iran-nexus APT assessed in the provided content as subordinate to Iran’s Ministry of Intelligence and Security (MOIS), active since at least 2017. Aliases explicitly mentioned in the content include Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, and TA450. The group is described as conducting espionage-oriented and other Iran-linked operations, and was identified by the Israel National Cyber Directorate among Iranian groups behind at least 15 phishing campaigns targeting Israeli public- and private-sector organizations. INCD stated these campaigns used tailored social-engineering lures such as fake Rafael job offers on LinkedIn, spoofed security-update emails, cash-offer scams, and academic conference invitations with malicious links, with the objective of gaining initial access and then moving deeper into victim organizations for espionage, damage, information gathering, and influence operations. The content also attributes to MuddyWater a spearphishing campaign targeting diplomatic, maritime, financial, telecommunications, and other sectors across the Middle East. In that activity, malicious Microsoft Word documents with VBA macros and icon spoofing were used to deliver a Rust-based implant referred to as RustyWater, aligned in the reporting with Archer RAT / RUSTRIC. The macros decoded a hex-embedded payload, wrote it to C:\ProgramData\CertificationKit.ini, and executed it via an obfuscated WScript.Shell/cmd.exe chain. Reported RustyWater capabilities include anti-debugging and anti-tampering via a vectored exception handler, host-information collection, string obfuscation with XOR, discovery of more than 25 antivirus/EDR products, persistence via a Windows Run registry key, asynchronous HTTP command-and-control using Rust reqwest and tokio, JSON/Base64/XOR multilayer data obfuscation for exfiltration, randomized jitter, and process injection into explorer.exe using VirtualAllocEx and WriteProcessMemory. The reporting characterizes this as an evolution from MuddyWater’s legacy PowerShell/VBS-heavy tradecraft toward a more modular, lower-noise Rust RAT.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Academia & Research
- Software & Services
Where they target
Geographies tied to known operations.
- 🇮🇱 Israel
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Observables
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iran-linked threat actor referenced as related threat intelligence for the outbreak.
Referenced as an Iranian regional actor historically involved in espionage, destructive attacks, and hack-and-leak activity in the context of the Middle East conflict.
Iran-linked espionage actor conducting spearphishing across Middle East sectors; uses icon spoofing and malicious Word docs to deliver Rust-based implants with async C2, anti-analysis, registry persistence, and modular post-compromise expansion.
Spearphishing campaign across the Middle East using malicious Word documents with VBA macros to drop a Rust-based implant ("RustyWater" / reported elsewhere as Archer RAT / RUSTRIC) that provides modular RAT functionality, anti-analysis, registry persistence, and asynchronous HTTP C2; includes process injection into explorer.exe for in-memory execution.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.