Actors Insights|Latest update27/08/2026
Cobalt Ulster
Named by SecureWorksSuspected state sponsor: Islamic Republic of IranCobalt Ulster is Secureworks' designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Secureworks documented Cobalt Ulster operations targeting government and telecommunications organizations in the Middle East using PowerShell-based implants and spear phishing lures. The group's consistent MOIS attribution and targeting profile — focused on regional government intelligence collection — aligns precisely with the broader MuddyWater/Seedworm/Mango Sandstorm cluster tracking across the industry.
First Seen:Jun 2019
Last Seen:Feb 2020
Indexed Reports:1
Public IOCs:30
Cluster: MuddyWaterMisp: MuddyWater
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)
Targeted Regions
AzerbaijanAzerbaijan
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
GeorgiaGeorgia
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
IraqIraq
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
JordanJordan
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
TurkeyTurkey
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
Jun 2019 ~ Feb 2020
Jan 2019Sep 2026
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.