Threats Feed|MuddyWater|Last Updated 04/05/2026|AuthorCertfa Radar|Publish Date09/03/2023

MuddyWater Masquerades as Hacktivists in Combined Extortion and Disinformation Campaign

  • Actor Motivations: Disinformation,Exfiltration,Sabotage
  • Attack Vectors: Vulnerability Exploitation,Ransomware,RAT,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

Iranian state-sponsored threat actor MuddyWater has aggressively targeted Israeli organizations in the finance, academia, and government sectors since late 2022. Operating under the guise of a hacktivist persona named "Darkbit," the group conducted a combined destructive ransomware and disinformation campaign against an academic institution in February 2023. Gaining access via phishing and exploiting vulnerabilities like Log4j, the attackers deployed custom Go-based ransomware alongside remote access tools like SyncroRAT and PowerShower. The operation involved both computer network exploitation, stealing 4TB of data—and computer network attacks, disrupting critical systems while demanding an exorbitant 80 Bitcoin ransom to mask their state-backed espionage and psychological objectives.

Detected Targets

TypeDescriptionConfidence
CaseTechnion Institute
The Technion – Israel Institute of Technology is a public research university located in Haifa, Israel. It was established in 1912 and is the oldest university in the country. Technion Institute has been targeted by MuddyWater as the main target.
Verified
SectorFinancial
Verified
SectorGovernment Agencies and Services
Verified
SectorUniversity
Verified
RegionIsrael
Verified

Extracted IOCs

  • 9880fae6551d1e9ee921f39751a6f3c0
  • 30466ccd4ec7bcafb370510855da2cd631f74b7a
  • 9107be160f7b639d68fe3670de58ed254d81de6aec9a41ad58d91aa814a247ff
download

Tip: 3 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 3 file hash) to this threat have been found.

Overlaps

MercuryMERCURY and DEV-1084's Destructive Cyber Operations Against Cloud and On-Premises Environments

Source: Microsoft - April 2023

Detection (one case): 9107be160f7b639d68fe3670de58ed254d81de6aec9a41ad58d91aa814a247ff

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The Darkbit Cyber Attack

A sophisticated cyber attack targeted organizations in Israel, resulting in the theft of sensitive data and the locking of critical computer systems. After disabling the systems, the attackers demanded an exceptionally high ransom to restore access. However, evidence suggests the primary goal was spreading political messages and causing operational disruption rather than collecting money.

The attack was carried out by MuddyWater, a state-sponsored hacking team directed by the Iranian government. To hide their true identity, the attackers operated under the fake name "Darkbit," pretending to be an independent group of politically motivated activists.

This incident combined a destructive computer lock-out with a political influence campaign. While the attackers demanded a massive financial payout, their true intentions were to disrupt business operations, steal data, and spread anti-Israeli propaganda under the guise of hacktivism.

The attack was highly disruptive, with the perpetrators claiming to have stolen four terabytes of organizational data. Following the data theft, they successfully locked numerous servers and individual workstations, causing major interruptions to business-critical systems.

Yes, the attackers specifically focused their efforts on the academic, financial, and government sectors within Israel. Technical evidence reveals that a major academic institution was a direct, pre-planned target, as the attackers had mapped out its specific computer network in advance.

The attackers initially broke into the networks using deceptive emails and by taking advantage of known software weaknesses that had not been properly updated. Once inside, they stole large amounts of data and launched a custom-built program that locked computer files while intentionally deleting system backups to prevent easy recovery.

Institutions in the academic, financial, and government sectors hold vast amounts of sensitive information, intellectual property, and critical operational data. Disrupting these high-profile organizations allows state-sponsored attackers to cause significant economic impact while maximizing the public visibility of their political messages.

Organizations should immediately apply software updates to fix known weaknesses, particularly those that attackers are actively exploiting to break into systems. It is also crucial to train staff to recognize deceptive emails and to monitor computer networks closely for any programs attempting to delete system backups.

This was a highly targeted and calculated operation rather than a random, widespread internet attack. The attackers specifically customized their malicious software and planned their intrusion to strike a pre-selected list of computers belonging to the targeted institution.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights