Threats Feed|MuddyWater|Last Updated 22/04/2026|AuthorCertfa Radar|Publish Date07/04/2026

MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Downloader,Dropper,Keylogger,Malicious Macro,Malware,RAT,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.

Detected Targets

TypeDescriptionConfidence
SectorDefense
Verified
SectorGovernment Agencies and Services
Verified
SectorAerospace
Verified
SectorEnergy
Verified
RegionIsrael
Verified
RegionUnited States
Verified

Extracted IOCs

  • mazafakaerindahouse[.]info
  • serialmenot[.]com
  • sharecodepro[.]com
  • ttrdomennew[.]com
  • 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90
  • 49f17c061a72cadaf9e3f90cc380e994883a965b7a4ad8953d8e8089c65908e6
  • 4aaf77c410f1f465d5e9063af60a07ad184e7a92ee87c973c2ea1542bfd66bff
  • 7ab597ff0b1a5e6916cad1662b49f58231867a1d4fa91a4edf7ecb73c3ec7fe6
  • 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444
  • a8c380b57cb7c381ca6ba845bd7af7333f52ee4dc4e935e98b48bb81facad72b
  • a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
  • bedb882c6e2cf896e14ecf12c90aaa6638f780017d1b8687a40b4a81956e230f
  • c8589ca999526f247db4d3902ade8a85619f8f82338c6230d1b935f413ddcb3d
  • d91f7a2962c0e9de3cd4ea9c770092d86b1641e89f0a7be2307b6451f00e5271
  • 157[.]20.182.49
  • 172[.]86.123.222
  • 23[.]94.145.120
download

Tip: 17 related IOCs (3 IP, 4 domain, 0 URL, 0 email, 10 file hash) to this threat have been found.

Overlaps

MuddyWaterFalse Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand

Source: Rapid7 - May 2026

Detection (two cases): 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0

MuddyWaterMuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization

Source: Oasis Security - April 2026

Detection (one case): 157[.]20.182.49

Void ManticoreIranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations

Source: Check Point - March 2026

Detection (three cases): 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444, a8c380b57cb7c381ca6ba845bd7af7333f52ee4dc4e935e98b48bb81facad72b, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0

MuddyWaterMuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs

Source: Huntress - March 2026

Detection (one case): 157[.]20.182.49

SeedwormIranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors

Source: Symantec - March 2026

Detection (four cases): 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90, 94f05495eb1b2ebe592481e01d3900615040aa02bd1807b705a50e45d7c53444, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0, serialmenot[.]com

MuddyWaterUnmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure

Source: Hunt.io - March 2026

Detection (one case): 157[.]20.182.49

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Demystifying the MuddyWater and CastleRAT Cyber Threat

An Iranian state-sponsored cyber espionage group was discovered using malicious software purchased from Russian cybercriminals. Instead of building their own hacking tools, the group bought an off-the-shelf system to upgrade their capabilities. This allowed them to launch sophisticated attacks while blending in with standard criminal activity.

The attacks were carried out by MuddyWater, a well-known cyber espionage group linked to Iran's Ministry of Intelligence and Security (MOIS). The tools they purchased and deployed belong to TAG-150, a Russian-speaking group that rents out its malware to other hackers.

The primary goal of this campaign is state-level espionage and data theft. By utilizing commercial malware, the attackers upgraded their ability to steal credentials, bypass modern security protections, and silently control compromised computers without the users noticing.

These campaigns remain highly active and operational. The attackers have continually updated their tools and launched new attacks throughout early 2026, maintaining a steady pace of operations even after their initial infrastructure was exposed by security researchers.

Yes. The attackers focused heavily on Israeli networks, specific web applications, and network security appliances. They have also actively targeted the United States aerospace sector, including sending highly specific phishing emails to an aerospace parts distributor.

The attackers tricked victims into opening deceptive files, such as malicious documents delivered via email. Once opened, these files silently installed hidden software that uses complex blockchain technology to securely communicate with the attackers' servers. The attackers could then secretly view the victim's screen and steal sensitive data.

Organizations in defense, aerospace, energy, and government sectors possess highly valuable intellectual property and national security secrets. Espionage groups target these entities to gain a geopolitical, military, or technological advantage for their host nation.

Organizations should strengthen their email security to intercept advanced phishing attempts and train staff to recognize industry-specific deceptive messages. Security teams must also update their monitoring tools to look for this specific blend of criminal malware being used for espionage, rather than writing it off as a standard virus.

This is a highly targeted threat aimed at specific geopolitical adversaries and high-value sectors, rather than a widespread attack on the general public. However, any organization within the defense, aerospace, energy, or government sectors should be on high alert.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights