Threats Feed|MuddyWater|Last Updated 04/05/2026|AuthorCertfa Radar|Publish Date14/04/2026

MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Brute-force,Vulnerability Exploitation,Backdoor
  • Attack Complexity: High
  • Threat Risk: High Impact/High Probability

Threat Overview

Oasis Security analyzed a multi-stage campaign attributed with medium-to-high confidence to MuddyWater, targeting critical infrastructure organizations across the Middle East — primarily Egypt, Israel, and the UAE — as well as Portugal and India. The operation began with large-scale automated reconnaissance, scanning more than 12,000 internet-exposed systems for five newly disclosed vulnerabilities affecting web applications, email servers, IT management platforms, and workflow automation tools. Following this broad scanning phase, the actor shifted to selective, high-value targeting: brute-forcing Outlook Web Access (OWA) credentials using custom tooling and multi-threaded frameworks such as Patator, with confirmed credential harvesting against organizations in Egypt, Israel, and the UAE. A modular, multi-protocol command-and-control (C2) infrastructure hosted in the Netherlands was used to manage compromised hosts, leveraging TCP, UDP, and HTTP channels with AES-encrypted communications — patterns consistent with the ArenaC2 framework previously associated with MuddyWater. The campaign resulted in confirmed exfiltration of sensitive data from an Egyptian aviation organization, including passport and visa records, payroll data, credit card information, and internal corporate documents. Approximately 200 files were staged in attacker-controlled directories prior to exfiltration, indicating structured data collection. The operation's timing — beginning in early February 2026, ahead of escalating regional tensions — suggests alignment with broader Iranian strategic intelligence objectives.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Government and public sector entities explicitly named as primary targets across Middle Eastern countries.
Verified
SectorEnergy
Energy and infrastructure companies explicitly listed as targeted sectors in the campaign.
High
SectorTransportation
Aviation organizations in Egypt explicitly named as targets; data exfiltrated from an Egyptian aviation entity.
Verified
RegionEgypt
Verified
RegionIndia
Verified
RegionIsrael
Verified
RegionPortugal
Verified
RegionUnited Arab Emirates
Verified

Extracted IOCs

  • 157[.]20.182.49
download

Tip: 1 related IOCs (1 IP, 0 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage

Source: JUMPSEC - April 2026

Detection (one case): 157[.]20.182.49

MuddyWaterMuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs

Source: Huntress - March 2026

Detection (one case): 157[.]20.182.49

MuddyWaterUnmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure

Source: Hunt.io - March 2026

Detection (one case): 157[.]20.182.49

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions

Researchers at Oasis Security identified a multi-stage cyberattack campaign starting in early February 2026. The attackers scanned more than 12,000 internet-facing systems for known vulnerabilities, then shifted to targeted credential theft and data theft against organizations in Egypt, Israel, the UAE, Portugal, and India. The campaign ultimately resulted in confirmed data being stolen from an aviation company in Egypt.

The campaign is attributed with medium-to-high confidence to MuddyWater, an Iranian state-linked threat group active since at least 2017. The attribution is based on the attack's command-and-control infrastructure sharing characteristics with the ArenaC2 framework previously associated with MuddyWater, as well as consistent multi-protocol communication patterns documented in prior MuddyWater operations.

The primary goals were intelligence collection and data theft. The attackers focused on stealing sensitive records — including passport and visa documents, payroll data, financial information, and internal corporate files — from high-value targets in the aviation, energy, and government sectors. The campaign's timing, beginning just ahead of escalating regional tensions in the Middle East, suggests it was aligned with Iranian strategic intelligence priorities.

The reconnaissance phase was wide — more than 12,000 internet-exposed systems were scanned globally. However, targeted intrusion attempts were regionally focused on the Middle East, specifically Egypt, Israel, and the UAE, with additional activity identified in Portugal and India. The confirmed data theft was limited to a single Egyptian aviation organization, though credential harvesting attempts were made against multiple organizations across these countries.

The campaign specifically targeted organizations in aviation, energy, and government — sectors with high operational and geopolitical significance. Confirmed victims and credential harvesting attempts were focused on entities in Egypt, Israel, and the UAE. An Egyptian aviation company suffered confirmed data theft. Government bodies and energy-sector organizations across the region were also targeted, reflecting the actor's interest in operationally sensitive infrastructure.

The attackers used a three-phase approach. First, they ran automated scans against more than 12,000 systems to identify those vulnerable to five newly disclosed software flaws. Second, they used custom scripts and tools to guess passwords on corporate email login pages (Outlook Web Access), gaining access to employee accounts. Finally, they installed modular command-and-control software on compromised systems, collected sensitive files, and transferred them to attacker-controlled servers hosted in the Netherlands — all while encrypting their communications to avoid detection.

Aviation, energy, and government organizations are priority targets for state-linked threat actors because they hold sensitive operational data, handle critical infrastructure, and carry significant geopolitical weight. For Iran-linked groups in particular, these sectors provide intelligence about regional military logistics, energy supply chains, and government operations — all of which have direct strategic value, especially during periods of heightened regional tension.

Organizations should immediately apply patches for CVE-2025-54068, CVE-2025-52691, CVE-2025-68613, CVE-2025-9316, and CVE-2025-34291. Multi-factor authentication should be enforced on all externally accessible services, especially Outlook Web Access and remote management tools. Security teams should monitor for repeated failed login attempts and unusual authentication patterns, block traffic from the known attacker IP (157.20.182[.]49), and inspect network logs for encrypted communications over non-standard ports. Any bulk file access or data staging activity on internal systems should be investigated promptly.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights