Actors Insights|Latest update24/07/2026

ENT-11

Named by NTTSHSuspected state sponsor: Islamic Republic of Iran

ENT-11 is NTT Security Holdings' tracking designation for the Iranian state-linked threat cluster publicly known as MuddyWater, attributed by US Cyber Command to Iran's Ministry of Intelligence and Security (MOIS). NTT documented ENT-11's use of a PowGoop variant dubbed E400, a DLL-based loader that masquerades as a legitimate Google Update executable and uses side-loading to execute obfuscated PowerShell backdoor scripts. PowGoop command and control servers associated with E400 were identified dating back to October 2020, targeting government, telecommunications, banking, and energy sector organizations primarily in the Middle East. The US government's formal attribution of PowGoop to MuddyWater in 2022 established it as a foundational tool in the cluster's offensive toolkit. NTT assessed ENT-11 would continue iterating on the toolset throughout 2022 and beyond, consistent with MuddyWater's documented pattern of rapid tool modification following public disclosure.

First Seen:Oct 2020
Last Seen:May 2022
Indexed Reports:1
Public IOCs:36
Cluster: Unclassified
also known as:
ENT-11 (NTTSH)

Targeted Regions

Middle East
ME
Middle East
Middle East
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Turkey
TR
Turkey
Turkey
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Oct 2020 ~ May 2022
Jan 2020Sep 2026

Targeted Sectors

BankingFinancialGovernment Agencies and Services

Recent Indexed Reports

  1. Public
    ENT-11: Iranian APT Group's PowGoop Attacks Uncovered

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.