- Home
- APT groups
- MuddyWater
APT group profile
MuddyWater
Cyberespionage group that the FBI, CISA, US Cyber Command and the UK's NCSC identify as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS). Active since at least 2017 against governments, telecommunications, energy and finance.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
MuddyWater (Seedworm, Static Kitten, Mango Sandstorm, TA450) is a cyberespionage group that, according to joint advisory AA22-055A from the FBI, CISA, US Cyber Command, the UK’s NCSC and NSA, operates as a subordinate element of Iran’s Ministry of Intelligence and Security (MOIS). MITRE ATT&CK places it as active since at least 2017 against governments and companies in telecommunications, defense, finance, and oil and gas. Its main focus is the Middle East, but it also operates in Asia, Africa, Europe and North America.
The group operates with volume and pragmatism. It combines spearphishing from compromised accounts, abuse of legitimate remote monitoring and management (RMM) tools, and a long series of custom backdoors, from POWERSTATS to recent Rust implants. ESET documented a joint sub-campaign with OilRig and assesses that MuddyWater may act as an initial access broker for other Iran-aligned groups.
For Latin America, the only public evidence is a Latin American financial services provider compromised in 2026, with no country specified, according to Symantec. As of this review, there are no reports of campaigns against Colombia.
Notable campaigns
- 2017: first documented campaigns using decoy documents and the POWERSTATS backdoor against targets in the Middle East (Unit 42).
- 2022: joint U.S.–UK advisory that attributes the group to the MOIS and describes PowGoop, Small Sieve, Canopy/STARWHALE, Mori and POWERSTATS (CISA).
- 2024: Hebrew-language payroll-themed emails and PDFs with links to file-sharing services that installed AteraAgent, aimed at Israeli employees of multinational companies (Proofpoint).
- 2024–2025: campaign against Israel and Egypt with the Fooder loader, the MuddyViper backdoor and the LP-Notes and CE-Notes credential stealers, plus a joint operation with OilRig (ESET).
- January–February 2026: “Operation Olalampo” against organizations and individuals in the MENA region, with malicious Office documents, new malware families and C2 via Telegram (Group-IB).
- February–March 2026: activity on the networks of a bank, an airport and other organizations in the U.S. and Canada with the Dindoor backdoor, which runs on the Deno runtime (Symantec).
- First quarter 2026: espionage campaign against at least nine organizations on four continents, including a South Korean manufacturer and a Latin American financial provider, using DLL sideloading and browser credential theft (Symantec).
Key TTPs
Resource development and initial access. Obtains and abuses legitimate tools such as ScreenConnect, RemoteUtilities, SimpleHelp and Atera (T1588.002). Sends spearphishing with attachments (T1566.001) and with links to file-sharing services (T1566.002), often from compromised third-party accounts. Has also exploited public-facing applications, such as Microsoft Exchange (CVE-2020-0688) (T1190).
Execution. Relies on the user opening the file or enabling macros (T1204.002) and, more recently, on ClickFix-style lures that ask the user to paste commands (T1204.004). Runs PowerShell and VBScript (T1059.001, T1059.005) and uses mshta.exe as a proxy (T1218.005).
Persistence, privilege escalation and evasion. Uses registry Run keys (T1547.001), scheduled tasks (T1053.005) and DLL sideloading (T1574.001). Obfuscates commands, for example with Invoke-Obfuscation and Base64 (T1027.010), and bypasses UAC (T1548.002).
Credentials and discovery. Dumps credentials from LSASS with Mimikatz and procdump (T1003.001) and from browsers (T1555.003). Collects system information (T1082).
C2 and exfiltration. Uses legitimate remote desktop software as a channel (T1219.002), C2 over HTTP (T1071.001) and proxies or compromised sites as relays (T1090.002). Has attempted to exfiltrate data to cloud storage (Wasabi) with Rclone (T1567.002).
Detection and mitigation
- RMM inventory: maintain an allowlist of approved remote administration tools and alert on new installations of Atera, ScreenConnect, SimpleHelp, Syncro, PDQ or similar, especially if they arrive via MSIs downloaded from file-sharing services (M1038). This is the highest-value signal against this group.
- Endpoint: log PowerShell (Script Block Logging, ID 4104) and monitor
mshta.exe,wscript.exeand Office → script chains (M1040, M1042). To detect ClickFix, look for PowerShell executions from the Run dialog (RunMRUkey). For sideloading, look for unsigned DLLs loaded by legitimate binaries from user paths. - Credentials: enable LSA protection and Credential Guard (M1043), restrict privileged accounts (M1026) and require MFA on email and VPN (M1032).
- Exposed attack surface: patch Exchange and other published services, prioritizing CISA’s KEV catalog (M1051).
- Network: alert on connections to non-corporate cloud storage services and on Rclone executions. Review outbound traffic to Telegram and the use of SOCKS tunnels from servers (M1031, M1037).
- Regional context: for financial institutions in LATAM, add the indicators from Symantec’s 2026 reports to your threat intelligence platforms and run retrospective hunts. The documented exposure in the region is isolated but recent.
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Resource Development
- T1588.002 Obtain Capabilities: Tool
Initial Access
Execution
Persistence
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation
- T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
Stealth
Credential Access
Discovery
- T1082 System Information Discovery
Command and Control
Exfiltration
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Malware and tools
References
Public sources this profile is based on.
- [1] MuddyWater, Group G0069 · MITRE ATT&CK, Jul 2026
- [2] Muddying the Water: Targeted Attacks in the Middle East · Palo Alto Networks Unit 42, Nov 2017
- [3] Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks (AA22-055A) · CISA / FBI / CNMF / NCSC / NSA, Feb 2022
- [4] Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign · Proofpoint, Mar 2024
- [5] MuddyWater: Snakes by the riverbank · ESET Research, Dec 2025
- [6] Operation Olalampo: Inside MuddyWater's Latest Campaign · Group-IB, Feb 2026
- [7] Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company · Symantec / Carbon Black Threat Hunter Team, Mar 2026
- [8] Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign · Symantec / Carbon Black Threat Hunter Team, May 2026
Profile last updated: