Saltar al contenido

Perfil de grupo APT

MuddyWater

Grupo de ciberespionaje que el FBI, CISA, US Cyber Command y el NCSC británico identifican como elemento subordinado del Ministerio de Inteligencia y Seguridad (MOIS) de Irán. Activo desde al menos 2017 contra gobiernos, telecomunicaciones, energía y finanzas.

MITRE G0069 Espionaje Actualizado

Técnicas MITRE ATT&CK

Técnicas atribuidas al grupo en fuentes públicas, agrupadas por táctica. Cada ID enlaza a attack.mitre.org.

Desarrollo de recursos

Acceso inicial

  • T1190 Exploit Public-Facing Application
  • T1566.001 Phishing: Spearphishing Attachment
  • T1566.002 Phishing: Spearphishing Link

Ejecución

  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1059.005 Command and Scripting Interpreter: Visual Basic
  • T1204.002 User Execution: Malicious File
  • T1204.004 User Execution: Malicious Copy and Paste
  • T1574.001 Hijack Execution Flow: DLL

Persistencia

  • T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Escalamiento de privilegios

  • T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Sigilo

  • T1027.010 Obfuscated Files or Information: Command Obfuscation
  • T1218.005 System Binary Proxy Execution: Mshta

Acceso a credenciales

  • T1003.001 OS Credential Dumping: LSASS Memory
  • T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Descubrimiento

  • T1082 System Information Discovery

Comando y control

  • T1071.001 Application Layer Protocol: Web Protocols
  • T1090.002 Proxy: External Proxy
  • T1219.002 Remote Access Tools: Remote Desktop Software

Exfiltración

  • T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Malware y herramientas

Referencias

Fuentes públicas en las que se basa este perfil.

  1. [1] MuddyWater, Group G0069 · MITRE ATT&CK, jul. 2026
  2. [2] Muddying the Water: Targeted Attacks in the Middle East · Palo Alto Networks Unit 42, nov. 2017
  3. [3] Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks (AA22-055A) · CISA / FBI / CNMF / NCSC / NSA, feb. 2022
  4. [4] Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign · Proofpoint, mar. 2024
  5. [5] MuddyWater: Snakes by the riverbank · ESET Research, dic. 2025
  6. [6] Operation Olalampo: Inside MuddyWater's Latest Campaign · Group-IB, feb. 2026
  7. [7] Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company · Symantec / Carbon Black Threat Hunter Team, mar. 2026
  8. [8] Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign · Symantec / Carbon Black Threat Hunter Team, may. 2026

Última actualización del perfil:

¿Le preocupa este grupo?

El servicio MDR de Ventura Systems monitorea 24/7 las técnicas de este y otros actores, con caza de amenazas basada en ATT&CK.