ENT-11
Named by NTTSHSuspected state sponsor: Islamic Republic of IranENT-11 is NTT Security Holdings' tracking designation for the Iranian state-linked threat cluster publicly known as MuddyWater, attributed by US Cyber Command to Iran's Ministry of Intelligence and Security (MOIS). NTT documented ENT-11's use of a PowGoop variant dubbed E400, a DLL-based loader that masquerades as a legitimate Google Update executable and uses side-loading to execute obfuscated PowerShell backdoor scripts. PowGoop command and control servers associated with E400 were identified dating back to October 2020, targeting government, telecommunications, banking, and energy sector organizations primarily in the Middle East. The US government's formal attribution of PowGoop to MuddyWater in 2022 established it as a foundational tool in the cluster's offensive toolkit. NTT assessed ENT-11 would continue iterating on the toolset throughout 2022 and beyond, consistent with MuddyWater's documented pattern of rapid tool modification following public disclosure.
Targeted Regions
Middle EastMiddle East
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
TurkeyTurkey
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.