Threats Feed|MuddyWater|Last Updated 27/08/2026|AuthorCertfa Radar|Publish Date21/11/2019

Excel-Based Macro Attacks: MuddyWater's Evolving Cyber Strategy

  • Actor Motivations: Espionage
  • Attack Vectors: Dropper,Malicious Macro,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: Low Impact/Low Probability

Threat Overview

The MuddyWater group conducted a cyberattack campaign during October-November 2019, employing spear phishing emails with macro-infected Excel documents. These emails delivered a file named “Report.xls,” which, when opened and macros were enabled, executed malicious activities including dropping files and creating network connections to a harmful domain. This campaign involved using legitimate Microsoft files for script execution and establishing command and control channels. NetWitness tools were utilized to highlight risky behaviors, registry changes for persistence, and unusual network communications.

Detected Targets

TypeDescriptionConfidence
RegionMiddle East Countries
High

Extracted IOCs

  • ampacindustries[.]com
  • annapolisfirstlimo[.]com
  • assignmenthelptoday[.]com
  • graphixo[.]net
  • ksahosting[.]net
  • 1cd71f39ff9fb3bf269440b63c717195
  • 269afae11cc9837e732019a03fa02fab
  • 2c3a634953a9a2c227a51e8eeac9f137
  • 32156247f900883d5106795ec103a624
  • 4022bbb9df5d86226bd9a89f361c94b9
  • 46f911014f1202e17936f627f34e6165
  • 50ac74eb38d6fa07d9f5e788d61a92cd
  • 584479a1958a73720c4aebb52c59b21e
  • 5ef459908d5be0672b02cdfe4f606989
  • 66c783e41480e65e287081ff853cc737
  • 7ed6c5e8c3ec4f9499eb793d69a06758
  • 9d0bfb81f450de8364327a4aaa67d9b3
  • a9706c01de9364eab210ea73296bfe71
  • b100c0cfbe59fa66cbb75de65c505ce2
  • b9ee416f2d9557be692abf448bf2f937
  • e18228bee6f1cf12eaf1bb4d5be587bf
  • 905e3f74e5dcca58cf6bb3afaec888a3d6cb7529b6e4974e417b2c8392929148
  • hxxp://ampacindustries[.]com/css/utf8.php
  • hxxp://graphixo[.]net/wp-includes/utf8.php
  • hxxp://ksahosting[.]net/wp-includes/utf8.php
  • hxxps://annapolisfirstlimo[.]com/editob.nvd
  • hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php
download

Tip: 27 related IOCs (0 IP, 5 domain, 5 URL, 0 email, 17 file hash) to this threat have been found.

Overlaps

Cobalt UlsterCobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security

Source: Secureworks - February 2020

Detection (six cases): hxxp://ksahosting[.]net/wp-includes/utf8.php, hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php, ampacindustries[.]com, assignmenthelptoday[.]com, graphixo[.]net, ksahosting[.]net

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

MuddyWater Cyber Attack Campaign

A state-sponsored cyber attack campaign was detected using malicious Excel documents to compromise organization systems. Once opened by a user, the infected spreadsheet drops hidden script files and establishes background connections to an external server.

The activity has been attributed to MuddyWater, a state-sponsored threat actor group suspected of having links to Iran. The group is known for conducting targeted cyber reconnaissance and espionage operations.

The campaign specifically targeted key regional infrastructure, focusing on organizations in the Telecommunications, Government, and Oil sectors across the Middle East. The primary goal involved establishing persistence on compromised endpoints and exfiltrating system and user identification details.

The attackers distributed spear-phishing emails carrying macro-enabled Excel attachments. When open, the file prompts the recipient to enable content, triggering macros that save and launch malicious script files, set up automatic startup entries, and communicate with an external domain over standard web traffic.

This is a highly targeted campaign directed at specific critical sectors within the Middle East rather than a broad, opportunistic attack against the general public.

Organizations should restrict macro execution in office applications, monitor endpoints for unusual startup registry entries or file creations in temporary folders, and leverage network security feeds to block known malicious domains.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights