Actors Insights|Latest update27/08/2026

Static Kitten

Named by CrowdStrikeSuspected state sponsor: Islamic Republic of Iran

Static Kitten is Anomali's designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Anomali documented Static Kitten conducting cyberespionage campaigns targeting UAE and Kuwait government agencies using legitimate remote desktop tools — particularly ScreenConnect — as part of its post-compromise toolkit. This characterization of the group's abuse of legitimate IT tools is consistent with broader MuddyWater tradecraft documented across other vendors, highlighting the cluster's preference for blending into normal enterprise IT management traffic to evade detection.

First Seen:Jun 2019
Last Seen:May 2026
Indexed Reports:1
Public IOCs:13
Cluster: MuddyWaterMitre: MuddyWaterMisp: MuddyWater
also known as:
TEMP.Zagros (Mandiant)Static Kitten (CrowdStrike)Seedworm (Symantec)MERCURY (Microsoft)COBALT ULSTER (SecureWorks)G0069 (Mitre)ATK51 (Thales)Boggy SerpensMango Sandstorm (Microsoft)TA450 (Proofpoint)Earth Vetala (Trend Micro)MuddyWater (Palo Alto)

Targeted Regions

Kuwait
KW
Kuwait
Kuwait
Jan 2021 ~ Feb 2021
United Arab Emirates
AE
United Arab Emirates
United Arab Emirates
Jan 2021 ~ Feb 2021
Jan 2021Oct 2026

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.