Actors Insights|Latest update27/08/2026

TEMP.Zagros

Named by MandiantSuspected state sponsor: Islamic Republic of Iran

TEMP.Zagros is Mandiant's designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Mandiant documented TEMP.Zagros conducting spear phishing campaigns against government and telecommunications targets in the Middle East and Central Asia using PowerShell-based implants and macro-laden Office documents. The name reflects Mandiant's geographic naming convention referencing the Zagros Mountains of Iran. TEMP.Zagros activity aligns closely with Symantec's Seedworm and Microsoft's Mercury tracking of the same cluster.

First Seen:Jan 2018
Last Seen:May 2026
Indexed Reports:1
Public IOCs:1,035
Cluster: MuddyWaterMitre: MuddyWaterMisp: MuddyWater
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)

Targeted Regions

India
IN
India
India
Jan 2018 ~ Mar 2018
Pakistan
PK
Pakistan
Pakistan
Jan 2018 ~ Mar 2018
Tajikistan
TJ
Tajikistan
Tajikistan
Jan 2018 ~ Mar 2018
Turkey
TR
Turkey
Turkey
Jan 2018 ~ Mar 2018
Jan 2018Aug 2026

Targeted Sectors

DefenseGovernment Agencies and Services

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.