Latest Update27/08/2026

Threats Feed

  1. Public

    MuddyWater's Cyber Arsenal: From PowGoop to Mori Backdoor

    US Cyber Command's Cyber National Mission Force (CNMF) published this advisory on January 12, 2022, disclosing multiple open-source tools used by MuddyWater — a subordinate element of Iran's Ministry of Intelligence and Security (MOIS) — in networks around the world. The advisory identifies several variants of the PowGoop malware suite and the Mori backdoor, and releases file samples to VirusTotal for defender use. PowGoop operates via DLL side-loading: the malicious goopdate.dll is placed alongside the legitimate GoogleUpdate.exe, causing it to load automatically. Once loaded, it deobfuscates a .dat PowerShell script, which in turn decodes a config.txt PowerShell script that establishes C2 communication using a modified Base64 encoding scheme. Additional PowGoop variants use different DLL names (libpcre2-8-0.dll, vcruntime140.dll) to avoid AV and manual detection. JavaScript samples associated with the same actor issue GET requests to malicious infrastructure. The Mori backdoor communicates with C2 infrastructure via DNS tunneling and is identified by two key indicators: creation of the mutex 0x50504060 and the registry key HKLM\SOFTWARE\NFC. CNMF noted that identifying multiple of these tools on the same network strongly indicates the presence of Iranian malicious cyber actors.

    read more about MuddyWater's Cyber Arsenal: From PowGoop to Mori Backdoor
  2. Public

    Evolution of MuddyWater: Targeting Governmental and Telecom Sectors in the Middle East

    The MuddyWater threat group continues to evolve its tactics and techniques. The group exploits publicly available offensive security tools and has been refining its custom toolset to avoid detection. It utilizes the PowGoop malware family, tunneling tools, and targets Exchange servers in high-profile organizations, particularly governmental entities and telecommunication companies in the Middle East. The group has also been observed exploiting CVE-2020-0688 and using Ruler for its malicious activities.

    read more about Evolution of MuddyWater: Targeting Governmental and Telecom Sectors in the Middle East
  3. Public

    Seedworm Group Suspected in Sweeping Espionage Campaign Across Telecom and IT Services

    An espionage campaign tentatively linked to the Iranian-backed Seedworm group has been using compromised organizations as stepping stones to additional victims or targets that may have been compromised solely to perform supply-chain-type attacks on other organizations. The attackers primarily used legitimate tools, publicly available malware, and living-off-the-land tactics, with a significant interest in Exchange Servers. While the ultimate end goal remains unknown, the focus on telecom operators suggests the attackers are gathering intelligence on the sector, potentially pivoting into communications surveillance.

    read more about Seedworm Group Suspected in Sweeping Espionage Campaign Across Telecom and IT Services
  4. Public

    MuddyWater Expands Its Reach: A Deep Dive into the Earth Vetala Intrusion

    The MuddyWater threat group, through an intrusion set named Earth Vetala, targeted various organizations in Azerbaijan, Bahrain, Israel, Saudi Arabia, and the United Arab Emirates. The group used spear-phishing emails to distribute malicious packages, predominantly aiming at Government Agencies, Academia, and the Tourism sector. MuddyWater deployed post-exploitation tools to dump passwords and establish a persistent presence within targeted systems. They used multiple C&C servers to execute obfuscated PowerShell scripts and were persistent in attempting multiple techniques to establish connectivity despite repeated failures.

    read more about MuddyWater Expands Its Reach: A Deep Dive into the Earth Vetala Intrusion
  5. Public

    Static Kitten Launches Cyberespionage Attack on UAE and Kuwait Government Sectors

    The cyberespionage group, Static Kitten, launched a cyber attack primarily targeting the government sectors of the United Arab Emirates (UAE) and Kuwait. Using geopolitical lures and masquerading as the Ministry of Foreign Affairs (MOFA) of Kuwait, the attackers aimed to install a remote management tool called ScreenConnect on victims' devices. The campaign involved phishing emails, URL masquerading, and delivering ZIP files that purport to contain relevant documents but instead initiate the ScreenConnect installation process.

    read more about Static Kitten Launches Cyberespionage Attack on UAE and Kuwait Government Sectors
  6. Public

    MuddyWater APT Group Linked to Steganography-Based Malware Attack

    A new malware strain, potentially linked to the MuddyWater APT group, uses Word files with macros to deploy PowerShell scripts from GitHub, which then download an image from Imgur. The image's pixel values decode a Cobalt Strike payload. This method, involving steganography, enables attackers to execute commands and establish remote control over Windows systems. The attack primarily targets Middle Eastern entities, using phishing emails to distribute malicious Word documents.

    read more about MuddyWater APT Group Linked to Steganography-Based Malware Attack
  7. Public

    Seedworm's Rising Activity: Middle East Targets and PowGoop Tool Connections

    The espionage group Seedworm (aka MuddyWater) has been actively targeting government organizations, telecoms, and computer services sectors across the Middle East, including Iraq, Turkey, Kuwait, the United Arab Emirates, Georgia, Afghanistan, Israel, Azerbaijan, Cambodia, and Vietnam. Seedworm's recent activities, linked to the PowGoop tool, involve PowerShell usage, credential dumping, and DLL side-loading. The group establishes connections to its infrastructure using Secure Sockets Funneling and Chisel while deploying PowGoop through remote execution tools. The connection between PowGoop and Seedworm remains tentative, suggesting potential retooling.

    read more about Seedworm's Rising Activity: Middle East Targets and PowGoop Tool Connections
  8. Public

    Operation Quicksand: MuddyWater's Escalation to Destructive Malware Tactics

    In September 2020, the Iranian threat actor MuddyWater launched "Operation Quicksand," as reported by the ClearSky cybersecurity company. This operation targeted Israeli organizations and others across the Middle East and North Africa, aiming to deploy a destructive variant of Thanos ransomware through "PowGoop," a malicious loader disguised as a Google update DLL. By employing spear-phishing, exploiting vulnerabilities, and using sophisticated malware delivery mechanisms, the campaign focused on destructive attacks rather than financial gain, marking a significant shift in MuddyWater's operational intent from espionage to more aggressive tactics.

    read more about Operation Quicksand: MuddyWater's Escalation to Destructive Malware Tactics
  9. Public

    Iranian APT MERCURY Exploits Zerologon in Persistent Cyber Campaigns

    Microsoft reports that the Iranian APT group MERCURY (aka MuddyWater) is actively exploiting the Zerologon vulnerability (CVE-2020-1472) to compromise Active Directory services. Known for targeting Middle Eastern governments for data exfiltration, MERCURY has also exploited the SharePoint vulnerability (CVE-2019-0604) to implant web shells for persistent access. These attacks often involve Cobalt Strike payloads and lateral movement within networks, focusing on domain controllers. Despite patches released in 2020, exploitation attempts remain widespread, highlighting the need for robust patch management. MERCURY's activities highlight the ongoing threat to governments and other critical sectors in the Middle East.

    read more about Iranian APT MERCURY Exploits Zerologon in Persistent Cyber Campaigns
  10. Public

    Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security

    In a series of espionage-focused campaigns, the Cobalt Ulster threat group, linked to the Iranian government, targeted governmental and intergovernmental organizations across Turkey, Jordan, Iraq, Georgia, and Azerbaijan from mid-2019 to mid-January 2020. These attacks primarily involved spearphishing with malicious attachments and links to compromised websites. The group used various techniques, including obfuscated macros in Excel files, VBScript, and PowerShell scripts for initial access and persistence. The campaigns featured sophisticated methods like DNS tunneling for command and control, and the use of tools for credential harvesting and establishing reverse SSL tunnels, indicating a high level of technical proficiency and strategic planning.

    read more about Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security
  11. Public

    Breathing New Life into MuddyC3: Unveiling the Upgraded Tools of MuddyWater

    In this report, the MuddyC3 tool used by MuddyWater is brought back to life. A group called “Green Leakers” on telegram were first to publish some information on this which triggered the writer of this article to go after the full technical aspect of this tool.This Python2.7 coded tool operates as a C2 server, deploying a PowerShell payload to the targeted system. The payload collects system information and reports back to the C2 server. Notably, the tool includes Base64 encoded PowerShell code to bypass AV detection.

    read more about Breathing New Life into MuddyC3: Unveiling the Upgraded Tools of MuddyWater
  12. Public

    Muddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike

    The Muddy Water threat actor, suspected to be a continuation of the previously reported BlackWater campaign, has been observed distributing malicious documents via spearphishing emails. One document focuses on the nomination of Stephen Moore to the Federal Reserve, likely leveraging current events for social engineering. Another targets the oil and gas sector and features a malicious macro named "H3OpAirStrike," potentially referencing historical Iranian air strikes. Both macros communicate with C2 servers and deploy PowerShell trojans. The malware collects various workstation data and uses Invoke-Obfuscation to evade detection.

    read more about Muddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike
  13. Public

    Excel-Based Macro Attacks: MuddyWater's Evolving Cyber Strategy

    The MuddyWater group conducted a cyberattack campaign during October-November 2019, employing spear phishing emails with macro-infected Excel documents. These emails delivered a file named “Report.xls,” which, when opened and macros were enabled, executed malicious activities including dropping files and creating network connections to a harmful domain. This campaign involved using legitimate Microsoft files for script execution and establishing command and control channels. NetWitness tools were utilized to highlight risky behaviors, registry changes for persistence, and unusual network communications.

    read more about Excel-Based Macro Attacks: MuddyWater's Evolving Cyber Strategy
  14. Public

    Muddyc3: The New Tool Powering MuddyWater's Cyber Espionage Operations

    The MuddyWater APT group carried out a series of spear-phishing attacks between February and April 2019. They targeted government entities, educational institutions, financial, telecommunication, and defense companies in Turkey, Iran, Afghanistan, Iraq, Tajikistan, and Azerbaijan. The group used a tool named muddyc3, capable of delivering a PowerShell payload and managing C&C server communication. Researchers discovered that the tool supports a variety of commands, indicating the use of a command-line interface. It also utilizes character substitution and base64 encoding for obfuscation.

    read more about Muddyc3: The New Tool Powering MuddyWater's Cyber Espionage Operations
  15. Public

    MuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

    The MuddyWater threat actor group has resurfaced, launching sophisticated campaigns against targets in the Middle East, Asia and other parts of the world, using new tools like the multi-stage PowerShell backdoor POWERSTATS v3 and various post-exploitation tools. The campaigns involved spear-phishing emails sent from compromised accounts, leading to the deployment of malware designed for intelligence gathering. Targets included a university in Jordan and the Turkish government, highlighting the group's continued focus on geopolitical espionage. The report also discusses MuddyWater's connections to Android malware and the use of false flags to misattribute campaigns, showcasing the group's evolving tactics and infrastructure sophistication.

    read more about MuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East
  16. Public

    MuddyWater’s Advanced Tactics Exploit CVE-2017-0199 in Global Campaigns

    The Iranian APT group MuddyWater has expanded its tactics, targeting government, telecommunications and military sectors in countries such as Tajikistan, Pakistan and Iraq. New campaigns include decoy documents exploiting CVE-2017-0199 and malicious VBA macros, with second-stage payloads downloaded from compromised servers. Primary targets have impersonated entities in the region surrounding Iran, including Iraqi and Pakistani organisations. The group also uses RATs for process detection, using obfuscation techniques such as Base64 encoding and JavaScript layers. Compromised servers in Pakistan and China facilitated these operations, demonstrating MuddyWater's sophisticated arsenal and focus on espionage.

    read more about MuddyWater’s Advanced Tactics Exploit CVE-2017-0199 in Global Campaigns
  17. Public

    MuddyWater's BlackWater: An In-depth Look at Advanced TTPs

    The MuddyWater-associated BlackWater campaign has displayed advanced TTPs in its latest activities. Using obfuscated VBA and PowerShell scripts, the threat actors establish persistence via registry keys and utilize multi-staging payloads. The campaign employs an open-source framework, FruityC2, to further enumerate the victim's host machine and evade signature-based detection mechanisms. The actor-controlled servers are used for command and control, making host-based detection challenging. Compared to earlier samples, the new tactics require a multi-step investigative approach.

    read more about MuddyWater's BlackWater: An In-depth Look at Advanced TTPs
  18. Public

    Decoding MuddyWater: Inside the APT's Advanced Toolset and Deception Tactics

    The MuddyWater APT group has been actively targeting governmental and telecommunications sectors in the Middle East, including Iraq, Saudi Arabia, Bahrain, Jordan, Turkey, and Lebanon, with additional activities in Azerbaijan, Pakistan, and Afghanistan. This report reveals the group's post-infection strategies, highlighting the deployment of custom-developed tools and scripts in Python, C#, and PowerShell for victim infiltration and data exfiltration. These tools include download/execute utilities, RATs, SSH scripts, and techniques for credential extraction and system information gathering. MuddyWater's deceptive tactics, such as impersonating other hacking groups and embedding misleading code strings, are also noted, aiming to complicate attribution and investigation efforts.

    read more about Decoding MuddyWater: Inside the APT's Advanced Toolset and Deception Tactics
  19. Public

    MuddyWater APT Targets Kurdish Political Groups and Turkish Defense Sector

    The Iranian APT group, MuddyWater, targeted Kurdish political groups and Turkish defense sector organizations using emails with malicious Word documents. The documents contained embedded Macros that used PowerShell to execute various commands and modify registry values for persistence. The Macro also used obfuscation techniques, encoding data within image files and a document. The attackers tested their malicious documents against various anti-virus engines, uploading files from Germany and Iraq. This campaign signifies an evolution in MuddyWater's attack methods, with malware extraction now performed locally rather than via a C2 server.

    read more about MuddyWater APT Targets Kurdish Political Groups and Turkish Defense Sector
  20. Public

    Advanced Spearphishing and PowerShell Backdoors: MuddyWater Targets Belarus, Turkey, and Ukraine

    The Iranian APT group MuddyWater has launched a new campaign targeting Belarus, Turkey, and Ukraine. Employing spearphishing as their primary infection vector, the attackers use socially engineered malicious documents to initiate a mainly fileless infection chain. These documents ultimately deliver POWERSTATS, a signature PowerShell backdoor capable of file exfiltration, script execution, and other malicious actions. The recent campaign also introduces a second-stage executable not written in PowerShell, which is packed with UPX and employs anti-analysis techniques. The executable gathers system information and communicates with a C&C server.

    read more about Advanced Spearphishing and PowerShell Backdoors: MuddyWater Targets Belarus, Turkey, and Ukraine
  21. Public

    MuddyWater Cyber Campaign Expands to Target Korek Telecom in Iraq

    The MuddyWater APT group is suspected of targeting Korek Telecom, a leading mobile operator in Iraq, through a sophisticated spear phishing campaign. The attack involved sending emails with malicious Office Word documents, urging victims to enable macros, which then executed a PowerShell backdoor. This approach enabled remote control of the victim's computer. The backdoor, known as POWERSTATS, was heavily obfuscated and facilitated data exfiltration and command execution via a C2 server. The group, traced back to early 2017, has expanded their attacks beyond Iran and Saudi Arabia to target government agencies, communication, oil companies, and educational institutions across Asia, Europe, and Africa.

    read more about MuddyWater Cyber Campaign Expands to Target Korek Telecom in Iraq
  22. Public

    SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants

    The provided report outlines the activities of a malware campaign leveraging the SeedWorm backdoor, specifically through variants of a program named LisfonService. These variants were developed and deployed using PowerShell to download and execute a malicious program, 'muddy', across targeted systems. Notably, the campaign utilizes filenames such as svchosts.exe and lisfon.exe to obscure its malicious intent.

    read more about SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants
  23. Public

    Seedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors

    Seedworm has compromised more than 130 victims across 30 organizations since September 2018. The group targets primarily the Middle East, Europe, and North America, focusing on government agencies, oil and gas companies, NGOs, telecoms, and IT firms. Seedworm uses tools such as Powermud, Powemuddy, and PowerShell scripts and has updated its tactics to avoid detection. The main targeted sectors include telecommunications, IT services, oil and gas, universities, and embassies. The group is known for its speed and agility in obtaining actionable intelligence from targeted organizations.

    read more about Seedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors
  24. Public

    Spear-Phishing and POWERSTAT: Dissecting MuddyWater's Latest Middle East Attacks

    In late November 2018, the Iranian APT group MuddyWater launched a new series of attacks in Middle East countries, targeting Lebanon, Oman, and Turkey. The campaign, consistent with their previous tactics since 2017, utilized spear-phishing emails with blurred documents to trick victims into enabling VB-macro code, subsequently infecting hosts with POWERSTAT malware. The attack involved creating a malicious Excel document for downloading further payloads, using PowerShell and JavaScript for execution delays, and establishing persistence through registry modifications and scheduled tasks. The POWERSTAT backdoor facilitated data exfiltration and remote command execution, highlighting MuddyWater's continued reliance on scripting languages and system tools for their objectives.

    read more about Spear-Phishing and POWERSTAT: Dissecting MuddyWater's Latest Middle East Attacks