Actors Insights|Latest update27/08/2026

UNC3313

Named by MandiantSuspected state sponsor: Islamic Republic of Iran

UNC3313 is Mandiant's unclassified threat cluster designation for a group assessed to be linked to MuddyWater, documented conducting espionage operations in late 2021. Mandiant tracked UNC3313 targeting government and private sector organizations in the Middle East using spear phishing and ScreenConnect remote access tool deployment — consistent with MuddyWater's known preference for legitimate remote administration tools. The UNC designation indicates Mandiant had not yet formally merged the activity into the TEMP.Zagros/MuddyWater cluster at time of reporting, though the technical and targeting overlaps are substantial.

First Seen:Nov 2021
Last Seen:Jan 2023
Indexed Reports:1
Public IOCs:13
Cluster: MuddyWater
also known as:
UNC3313 (Mandiant)

Targeted Regions

Middle East
ME
Middle East
Middle East
Nov 2021 ~ Feb 2022
Nov 2021 ~ Feb 2022
Jan 2021Oct 2026

Targeted Sectors

Government Agencies and ServicesInformation TechnologyTelecommunication

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.