Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecybercrime-service-ecosystemcommand-and-control-methodgovernment-diplomatic-threat

MuddyWater Linked to Iranian MOIS Uses Russian MaaS in ChainShell Campaign

Updated 28d agoFirst seen Apr 9, 20264 sources

Iran-linked threat group MuddyWater has been tied to a ChainShell campaign that reportedly uses Russian malware-as-a-service infrastructure, underscoring growing overlap between state-backed espionage and criminal tooling. Reporting on the activity said the operation relied on blockchain-based command-and-control and reflected operational links between the Iran-aligned actor and Russian cybercrime services, extending a long-running pattern of MuddyWater adapting external tools and tradecraft for intrusion operations.

U.S. and allied agencies have previously attributed MuddyWater to Iran’s Ministry of Intelligence and Security (MOIS) and described the group as targeting government and commercial organizations across Asia, Africa, Europe, and North America, including telecommunications, defense, local government, and oil and gas. Public reporting and government advisories say the group has used spearphishing, exploitation of known flaws such as CVE-2020-0688 and CVE-2020-1472, DLL side-loading, obfuscated PowerShell, and malware including PowGoop, Mori, Small Sieve, Canopy/Starwhale, and POWERSTATS to establish access, maintain persistence, exfiltrate data, and in some cases deploy ransomware.

Share:
MuddyWater Linked to Iranian MOIS Uses Russian MaaS in ChainShell Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 7, 20263mo ago

New reporting highlights MuddyWater's ChainShell attack activity

A 2026 report described MuddyWater as using Russian malware-as-a-service in a new ChainShell attack. This appears to be continued reporting on the ChainShell activity and its operational links to Russian criminal tooling.

May 8, 20233y ago

JUMPSEC reports ChainShell linking MuddyWater to Russian MaaS

JUMPSEC threat intelligence reported a ChainShell campaign or capability in which the Iran-aligned MuddyWater actor used Russian malware-as-a-service. The reporting also said the activity relied on blockchain-based command-and-control infrastructure, highlighting overlap between state-aligned operations and cybercriminal services.

Feb 24, 20224y ago

Five Eyes and U.S. agencies publish joint MuddyWater advisory

On February 24, 2022, the FBI, CISA, U.S. Cyber Command CNMF, NSA, and NCSC-UK issued a joint advisory on Iranian government-sponsored MuddyWater activity. The advisory detailed TTPs, malware, exploited vulnerabilities including CVE-2020-1472 and CVE-2020-0688, and recommended mitigations and IOCs.

Jan 13, 20224y ago

USCYBERCOM publicly links MuddyWater to Iran's MOIS

US Cyber Command publicly attributed MuddyWater to Iran’s Ministry of Intelligence and Security, identifying it as a subordinate element involved in Iranian intelligence operations. It also uploaded malware samples and JavaScript artifacts associated with the group to VirusTotal to aid defenders.

Nov 1, 20179y ago

MuddyWater conducts MOIS-linked espionage campaigns globally

By approximately 2018, Iranian government-sponsored MuddyWater activity was targeting government and commercial organizations across Asia, Africa, Europe, and North America. The group used spearphishing, known vulnerability exploitation, DLL side-loading, obfuscated PowerShell, and malware families such as PowGoop, Mori, and POWERSTATS.

Feb 1, 20179y ago

MuddyWater begins sustained cyber operations

MuddyWater is described as having conducted campaigns since at least 2017, initially targeting organizations in the Middle East and later expanding into Europe and North America. Reported victim sectors included telecommunications, government IT services, and oil.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Threat actors
1 linked
Organizations
1 linked
JUMPSEC
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.