Actors Insights|Latest update27/08/2026

TA450

Named by ProofpointSuspected state sponsor: Islamic Republic of Iran

TA450 is Proofpoint's designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Active since at least 2024 in Proofpoint's tracking, TA450 conducts spear phishing campaigns using PDF attachments with embedded links targeting Israeli organizations, as well as government and finance sector targets in the Middle East. Proofpoint documented the group's use of legitimate remote management tools alongside phishing campaigns — consistent with MuddyWater's established tradecraft — and noted a campaign focus on Israeli targets coinciding with geopolitical tensions following October 2023.

First Seen:Mar 2024
Last Seen:Apr 2026
Indexed Reports:1
Public IOCs:3
Cluster: MuddyWaterMitre: MuddyWaterMisp: MuddyWater
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)

Targeted Regions

Israel
IL
Israel
Israel
Mar 2024 ~ Mar 2024
Jan 2024Nov 2026

Targeted Sectors

Information TechnologyManufacturing

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.