Skip to content

APT group profile

MuddyWater

Cyberespionage group that the FBI, CISA, US Cyber Command and the UK's NCSC identify as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS). Active since at least 2017 against governments, telecommunications, energy and finance.

MITRE G0069 Espionage LATAM Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Resource Development

Initial Access

  • T1190 Exploit Public-Facing Application
  • T1566.001 Phishing: Spearphishing Attachment
  • T1566.002 Phishing: Spearphishing Link

Execution

  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1059.005 Command and Scripting Interpreter: Visual Basic
  • T1204.002 User Execution: Malicious File
  • T1204.004 User Execution: Malicious Copy and Paste
  • T1574.001 Hijack Execution Flow: DLL

Persistence

  • T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Privilege Escalation

  • T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Stealth

  • T1027.010 Obfuscated Files or Information: Command Obfuscation
  • T1218.005 System Binary Proxy Execution: Mshta

Credential Access

  • T1003.001 OS Credential Dumping: LSASS Memory
  • T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Discovery

  • T1082 System Information Discovery

Command and Control

  • T1071.001 Application Layer Protocol: Web Protocols
  • T1090.002 Proxy: External Proxy
  • T1219.002 Remote Access Tools: Remote Desktop Software

Exfiltration

  • T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Malware and tools

References

Public sources this profile is based on.

  1. [1] MuddyWater, Group G0069 · MITRE ATT&CK, Jul 2026
  2. [2] Muddying the Water: Targeted Attacks in the Middle East · Palo Alto Networks Unit 42, Nov 2017
  3. [3] Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks (AA22-055A) · CISA / FBI / CNMF / NCSC / NSA, Feb 2022
  4. [4] Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign · Proofpoint, Mar 2024
  5. [5] MuddyWater: Snakes by the riverbank · ESET Research, Dec 2025
  6. [6] Operation Olalampo: Inside MuddyWater's Latest Campaign · Group-IB, Feb 2026
  7. [7] Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company · Symantec / Carbon Black Threat Hunter Team, Mar 2026
  8. [8] Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign · Symantec / Carbon Black Threat Hunter Team, May 2026

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.