Actors Insights|Latest update27/08/2026
TEMP.Zagros
Named by MandiantSuspected state sponsor: Islamic Republic of IranTEMP.Zagros is Mandiant's designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Mandiant documented TEMP.Zagros conducting spear phishing campaigns against government and telecommunications targets in the Middle East and Central Asia using PowerShell-based implants and macro-laden Office documents. The name reflects Mandiant's geographic naming convention referencing the Zagros Mountains of Iran. TEMP.Zagros activity aligns closely with Symantec's Seedworm and Microsoft's Mercury tracking of the same cluster.
First Seen:Jan 2018
Last Seen:May 2026
Indexed Reports:1
Public IOCs:1,035
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)
Targeted Regions
IndiaIndia
Jan 2018 ~ Mar 2018
PakistanPakistan
Jan 2018 ~ Mar 2018
TajikistanTajikistan
Jan 2018 ~ Mar 2018
TurkeyTurkey
Jan 2018 ~ Mar 2018
Jan 2018Aug 2026
Targeted Sectors
DefenseGovernment Agencies and Services
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.