Threats Feed|MuddyWater|Last Updated 05/05/2026|AuthorCertfa Radar|Publish Date10/04/2019

Advanced Spearphishing and PowerShell Backdoors: MuddyWater Targets Belarus, Turkey, and Ukraine

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Dropper,Fileless malware,Malicious Macro,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

The Iranian APT group MuddyWater has launched a new campaign targeting Belarus, Turkey, and Ukraine. Employing spearphishing as their primary infection vector, the attackers use socially engineered malicious documents to initiate a mainly fileless infection chain. These documents ultimately deliver POWERSTATS, a signature PowerShell backdoor capable of file exfiltration, script execution, and other malicious actions. The recent campaign also introduces a second-stage executable not written in PowerShell, which is packed with UPX and employs anti-analysis techniques. The executable gathers system information and communicates with a C&C server.

Detected Targets

TypeDescriptionConfidence
SectorFinancial
Medium
RegionBelarus
Verified
RegionTurkey
Verified
RegionUkraine
Verified

Extracted IOCs

  • orbe-fzc[.]com
  • 08e256cd2fa027552be253ec3bf427b537977f9123adf1f36e7cd2843a057554
  • 2f77ec3dd5a5c8146213fdf6ac2df4a25a542cbd809689a5642954f2097e037a
  • 925225002364615b964e4e3704876d9b101e4f07169dbb459175248aefb5a0ad
  • 93b749082651d7fc0b3caa9df81bad7617b3bd4475de58acfe953dfafc7b3987
  • c005e11a037210eb8efe12b8dee794be36151de30b0223f2c9c4b9680cb033c0
  • c873532e009f2fc7d3b111636f3bbaa307465e5a99a7f4386bebff2ef8a37a20
  • 185[.]117.75.116
download

Tip: 8 related IOCs (1 IP, 1 domain, 0 URL, 0 email, 6 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

Source: Trend Micro - June 2019

Detection (one case): 185[.]117.75.116

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Demystifying the Latest MuddyWater Cyberattacks

Cybersecurity researchers have discovered a new cyberattack campaign targeting organizations in Belarus, Turkey, and Ukraine. Attackers used highly deceptive emails and malicious documents to secretly install software on victims' computers. Once installed, this software gathers system information and establishes a backdoor for further malicious activity.

The attack is attributed to MuddyWater, an Iranian advanced persistent threat (APT) group. They have been active since at least 2017 and are widely known for their effective phishing campaigns and ability to quietly steal data from compromised networks.

The primary goal of this campaign is unauthorized access and data theft. The attackers steal legitimate documents from networks they have already breached, secretly weaponize them, and send them to new victims. This allows them to map out the newly infected computers and prepare to steal additional files.

This specific campaign is focused on organizations within Belarus, Turkey, and Ukraine. Rather than using a massive, scattergun approach, the campaign spreads deliberately by using stolen documents from one compromised organization to infect the next.

While the report does not list every specific industry, the attackers heavily target organizations by spoofing real corporate and government entities. For example, they used a malicious document disguised as a legal update from the Capital Markets Board of Turkey to trick specific regional victims.

Attackers send targeted emails containing fake but highly convincing documents. If a user is tricked into clicking a prompt to "enable content" within the document, hidden software runs in the background. This software gathers computer details, checks its internet connection, and connects to an attacker-controlled server to download further malicious instructions.

Organizations in these regions likely possess sensitive internal data, intellectual property, or strategic communications. By successfully compromising these networks, attackers gain access to valuable intelligence while using the organization's trusted name to launch further attacks.

Organizations should train their staff to easily recognize suspicious emails and strictly avoid enabling macros or content in unsolicited documents. Furthermore, IT teams should monitor computer networks for unauthorized programs running in hidden background folders and block connections to known malicious web addresses.

This is a highly targeted issue. The attackers use customized, socially engineered messages—such as drafting decoy text specifically in the Turkish language—tailored to deceive their intended regional victims rather than attacking the general public.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights