Threats Feed|MuddyWater|Last Updated 26/08/2026|AuthorCertfa Radar|Publish Date21/03/2019

MuddyWater Cyber Campaign Expands to Target Korek Telecom in Iraq

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Dropper,Malicious Macro,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: Low Impact/Low Probability

Threat Overview

The MuddyWater APT group is suspected of targeting Korek Telecom, a leading mobile operator in Iraq, through a sophisticated spear phishing campaign. The attack involved sending emails with malicious Office Word documents, urging victims to enable macros, which then executed a PowerShell backdoor. This approach enabled remote control of the victim's computer. The backdoor, known as POWERSTATS, was heavily obfuscated and facilitated data exfiltration and command execution via a C2 server. The group, traced back to early 2017, has expanded their attacks beyond Iran and Saudi Arabia to target government agencies, communication, oil companies, and educational institutions across Asia, Europe, and Africa.

Detected Targets

TypeDescriptionConfidence
CaseKorek Telecom
Korek Telecom is an Iraqi Kurdish mobile phone operator company in Erbil, Kurdistan Region. Korek Telecom has been targeted by MuddyWater as the main target.
Verified
SectorTelecommunication
Verified
RegionIraq
Verified

Extracted IOCs

  • 09aabd2613d339d90ddbd4b7c09195a9
  • 0d69debf5b805b0798429e5fca91cb99
  • 806adc79e7ea3be50ef1d3974a16b7fb
  • 83c31845c0de88578cf94c9655654795
  • a61b268e9bc9b7e6c9125cdbfb1c422a
  • cf3c731ca73ddec5d9cdd29c680c0f20
  • 46[.]105.84.146
  • 94[.]23.148.194
  • 94[.]23.148.194/serverscript/clientfrontline/getcommand[.]php
  • 94[.]23.148.194/serverscript/clientfrontline/helloserver[.]php
  • 94[.]23.148.194/serverscript/clientfrontline/setcommandresult[.]php
download

Tip: 11 related IOCs (2 IP, 0 domain, 3 URL, 0 email, 6 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater APT's Evolving Tactics: From Macros to RMM Tool Abuse

Source: Genians - February 2026

Detection (one case): 806adc79e7ea3be50ef1d3974a16b7fb

MuddyWaterBlackWater Campaign: MuddyWater's Advanced Evasion and Persistence Techniques

Source: Rewterz - May 2019

Detection (two cases): 94[.]23.148.194, cf3c731ca73ddec5d9cdd29c680c0f20

MuddyWaterMuddyWater's BlackWater: An In-depth Look at Advanced TTPs

Source: Cisco Talos - May 2019

Detection (one case): 94[.]23.148.194

MuddyWaterMuddyWater APT Targets Kurdish Political Groups and Turkish Defense Sector

Source: ClearSky - April 2019

Detection (three cases): 46[.]105.84.146, 94[.]23.148.194, 09aabd2613d339d90ddbd4b7c09195a9

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

MuddyWater Cyberattack on Korek Telecom

A targeted cyberattack attempted to compromise the internal systems of Korek Telecom, a major mobile operator in Iraq. Threat actors delivered phishing emails containing malicious Word documents designed to trick employees into enabling macros, which silently installed background remote-access software onto their workstations.

The attack is suspected to be conducted by MuddyWater, a cyber espionage group believed to operate out of Iran. Active since early 2017, the group is known for targeting government agencies, telecommunications providers, energy sector organizations, military targets, and educational institutions.

The primary goal of the operation was espionage and persistent remote surveillance. By deploying the POWERSTATS backdoor, the attackers aimed to establish long-term access to company systems, collect detailed information about the network and infected machines, and execute remote commands.

This specific incident was a targeted operation directed directly at Korek Telecom's workforce rather than a broad, random malware outbreak. While MuddyWater conducts espionage campaigns across multiple continents, this attack specifically tailored its email messaging to Korek Telecom employees.

The attackers specifically targeted Korek Telecom employees using their corporate email addresses (@korektel.com). The assets targeted included computer system names, usernames, local and public IP addresses, and underlying telecommunications workstation access.

The attackers sent emails posing as company insiders claiming an attached document detailed an error in a March business report. When opened, the document displayed a fake error message to confuse the user while secretly writing persistent startup scripts to the system registry to launch PowerShell backdoors automatically upon system reboot.

As Iraq's fastest-growing telecommunications company, Korek Telecom serves 18 provinces across corporate, government, and individual user segments. Gaining unauthorized access to a major telecom operator provides threat actors with high-value strategic opportunities for intelligence gathering and network monitoring.

Organizations should block macro execution by default across Office applications, implement strict email inspection filters, and continuously monitor system startup registries. Individuals should avoid enabling content or macros in unexpected email attachments, even if the message appears to originate from an internal source.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights