Threats Feed|MuddyWater|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date18/04/2023

MuddyWater APT Uses Legitimate Remote Management Tool for Persistence

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

Group-IB's April 2023 report documents MuddyWater's use of SimpleHelp, a legitimate remote device management tool, as a persistence mechanism on victim devices. Group-IB identified this technique in fall 2022 through retrospective analysis of MuddyWater infrastructure using their Threat Intelligence platform. SimpleHelp is not compromised — the threat actors download it directly from the official website and deploy it to maintain persistent, stealthy remote access to victim systems. The SimpleHelp client runs as a system service, surviving reboots and enabling operators to connect at any time, execute commands with administrator privileges, and perform covert terminal access. As of publication, at least eight MuddyWater servers had SimpleHelp installed. Group-IB also uncovered previously unknown MuddyWater infrastructure by tracking three unique HTTP ETag hashes (2aa6-5c939a3a79153, 2aa6-5b27e6e58988b, 2aa6-5c939a773f7a2) consistent across the group's VPS fleet, linking 63 IP addresses to MuddyWater activity. One incident response case in fall 2022 at a Middle Eastern organization confirmed active use of 164.132.237.65 — a server that also hosted Cobalt Strike with a custom, watermark-free configuration file. A shortcut LNK file linked to IP 91.121.240.108 targeted a UAE Ministry of Health and Prevention lure (mohap.gov.ae). An additional PowerShell backdoor script linked to 91.121.240.96 was uploaded to VirusTotal from Kazakhstan. The distribution method for SimpleHelp is unconfirmed but likely involves phishing emails with links to OneDrive, Onehub, or Dropbox. Post-installation lateral movement likely involves Fast Reverse Proxy (FRP) or Ligolo.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
None
Verified
SectorTelecommunication
None
Verified
SectorUtilities
None
Verified
RegionTurkey
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • 306555c68c4444466601c854aeb499fd
  • 3ad3ae6fdd307c040743d23152334225
  • a491a855bd1af4d93c49002be04584f5
  • 6d2fa13350bfe444da2e97eba7fe92ee6d2cd47f
  • 820c8719f3dff8e0e5c990d7cc0a7aabb22fcf1d
  • c99194d8772647012d47a4fbc18f79b87e1f0a3b
  • 2528838a609aa143769efb37dff45af723868d4ed33eb1ce0e2d6ce64b2a1507
  • 504a9b79bc05cc355508e04f56bb106f2488bd04d051337fa524fd2211bd5f53
  • 5366c1937b22c377843a04b716cd62fb57b3ed36042f6af11a403dcfc63608e0
  • 137[.]74.131.16
  • 137[.]74.131.18
  • 137[.]74.131.19
  • 137[.]74.131.20
  • 137[.]74.131.22
  • 137[.]74.131.24
  • 137[.]74.131.30
  • 141[.]95.177.129
  • 141[.]95.177.130
  • 141[.]95.177.131
  • 141[.]95.177.132
  • 141[.]95.177.133
  • 141[.]95.177.134
  • 141[.]95.177.135
  • 141[.]95.177.142
  • 141[.]95.177.143
  • 149[.]202.242.80
  • 149[.]202.242.84
  • 149[.]202.242.85
  • 149[.]202.242.86
  • 149[.]202.242.87
  • 151[.]80.172.146
  • 151[.]80.172.147
  • 151[.]80.172.149
  • 164[.]132.237.64
  • 164[.]132.237.65
  • 164[.]132.237.66
  • 164[.]132.237.70
  • 164[.]132.237.71
  • 164[.]132.237.74
  • 164[.]132.237.75
  • 164[.]132.237.76
  • 164[.]132.237.78
  • 178[.]32.30.0
  • 178[.]32.30.1
  • 178[.]32.30.2
  • 178[.]32.30.3
  • 37[.]187.204.25
  • 37[.]187.204.26
  • 51[.]254.25.36
  • 51[.]255.19.178
  • 51[.]255.19.179
  • 51[.]255.19.183
  • 51[.]83.56.226
  • 5[.]196.249.161
  • 5[.]196.249.162
  • 91[.]121.240.100
  • 91[.]121.240.101
  • 91[.]121.240.102
  • 91[.]121.240.103
  • 91[.]121.240.104
  • 91[.]121.240.105
  • 91[.]121.240.106
  • 91[.]121.240.107
  • 91[.]121.240.108
  • 91[.]121.240.109
  • 91[.]121.240.110
  • 91[.]121.240.111
  • 91[.]121.240.96
  • 91[.]121.240.98
  • 91[.]121.240.99
  • 91[.]134.169.137
  • 91[.]134.169.139
download

Tip: 72 related IOCs (63 IP, 0 domain, 0 URL, 0 email, 9 file hash) to this threat have been found.

Overlaps

MuddyWaterDarkBeatC2: MuddyWater's Latest Framework Targets Israeli Networks

Source: Deep Instinct - April 2024

Detection (one case): 137[.]74.131.19

UnclassifiedState-Sponsored Cyberattacks Target Israeli Academia and Government Sectors

Source: Israel National Cyber Directorate - March 2024

Detection (six cases): 137[.]74.131.18, 137[.]74.131.19, 141[.]95.177.134, 91[.]121.240.102, 91[.]121.240.106, 91[.]121.240.98

MuddyWaterMuddyWater's Shift to MuddyC2Go Framework Targets Jordan, Iraq, and Israel

Source: Deep Instinct - November 2023

Detection (five cases): 137[.]74.131.18, 137[.]74.131.20, 141[.]95.177.130, 164[.]132.237.65, 91[.]121.240.108

MuddyWaterMuddyWater Upgrades: The Emergence of PhonyC2 Framework

Source: Deep Instinct - June 2023

Detection (seven cases): 137[.]74.131.16, 137[.]74.131.18, 137[.]74.131.24, 137[.]74.131.30, 178[.]32.30.3, 51[.]255.19.178, 91[.]121.240.104

MercuryMERCURY Turns to SysAid Applications for Targeted Cyberattacks in Israel

Source: Microsoft - August 2022

Detection (two cases): 164[.]132.237.64, 91[.]121.240.104

ENT-11ENT-11: Iranian APT Group's PowGoop Attacks Uncovered

Source: NTT Security - May 2022

Detection (five cases): 164[.]132.237.65, 164[.]132.237.66, 178[.]32.30.1, 51[.]255.19.178, 51[.]255.19.179

MuddyWaterMuddyWater's Strategic Cyber Campaigns Across Turkey, Armenia, and Pakistan

Source: Cisco Talos - March 2022

Detection (one case): 178[.]32.30.3

MuddyWaterMuddyWater: Iranian APT Group Targets Global Networks Across Multiple Sectors

Source: CISA - February 2022

Detection (one case): 164[.]132.237.65

MuddyWaterEvolving Threat: MuddyWater APT's Multi-National Cyber Espionage Activities

Source: Cisco Talos - January 2022

Detection (two cases): 137[.]74.131.16, 149[.]202.242.84

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About MuddyWater's SimpleHelp Persistence Campaign

Group-IB's Threat Intelligence platform discovered in fall 2022 that MuddyWater, an Iranian-linked APT group, had begun deploying SimpleHelp — a legitimate remote device management tool — as a persistence mechanism on victim systems in the Middle East and Turkey. The group downloaded SimpleHelp directly from the official vendor website and installed it as a Windows service on compromised machines, giving operators persistent remote access that survives reboots. Group-IB published its full infrastructure analysis in April 2023, documenting 63 IP addresses linked to MuddyWater activity and a unique ETag-based server fingerprint the group leaves on its VPS infrastructure.

The campaign is attributed to MuddyWater, an Iranian state-sponsored threat group assessed to be a subordinate element of Iran's Intelligence Ministry (MOIS). The group is also tracked as TEMP.Zagros, Seedworm, Static Kitten, SectorD02, TA450, Boggy Serpens, and MERCURY. Group-IB linked the SimpleHelp activity to MuddyWater through confirmed IP address overlap with publicly known MuddyWater infrastructure, consistent ETag hashes across their VPS fleet, and a matching Cobalt Strike server linked to an active incident response case involving confirmed MuddyWater TTPs.

The primary goal was establishing persistent, covert remote access to victim systems for intelligence collection. By using a legitimate, digitally signed tool like SimpleHelp — rather than custom malware — MuddyWater can maintain long-term access that evades traditional security tools relying on malicious file detection. Once installed, operators can execute commands with administrator privileges, transfer files, and pivot through networks at any time, including after system reboots, with minimal forensic footprint.

Targeting covered organizations in the Middle East and Turkey, consistent with MuddyWater's broader focus on Iran's regional adversaries and neighboring states. Group-IB's top ten target countries for MuddyWater include Turkey, Pakistan, UAE, Iraq, Israel, Saudi Arabia, Jordan, USA, Azerbaijan, and Afghanistan. An active incident response case at a Middle Eastern organization in November 2022 confirmed deployment of Cobalt Strike linked to this infrastructure. A UAE Ministry of Health lure (mohap.gov.ae) was also identified, and a PowerShell backdoor was uploaded to VirusTotal from Kazakhstan, indicating active operations across the region.

MuddyWater's use of legitimate remote management tools is a deliberate strategy to bypass traditional security controls. Tools like SimpleHelp, ScreenConnect, RemoteUtilities, and Syncro are commercially available, digitally signed, and commonly used by IT departments — meaning antivirus and endpoint detection tools based on file signatures will not flag them as malicious. The tool runs as a persistent Windows service that survives reboots. When an operator connects, the session looks identical to a legitimate IT support session, making behavioral detection the only viable method for identification. This approach also gives the group plausible deniability since the tool itself is not weaponized.

Victims receive a spearphishing email — likely containing a link to a cloud storage service such as OneDrive, Onehub, or Dropbox — that delivers a SimpleHelp installer. Once the victim runs the installer, SimpleHelp installs itself as a persistent Windows service that automatically starts on reboot. MuddyWater operators then connect at any time through their SimpleHelp server, giving them full remote control of the victim's device including terminal access with administrator privileges, file transfer, and command execution. Post-access activity likely includes deployment of Fast Reverse Proxy (FRP) or Ligolo for network pivoting, and Cobalt Strike for deeper post-exploitation.

Group-IB identified that MuddyWater consistently uses the same set of components when provisioning web servers on purchased VPS infrastructure, leaving three unique HTTP ETag hashes behind: 2aa6-5c939a3a79153, 2aa6-5b27e6e58988b, and 2aa6-5c939a773f7a2. By searching for these ETag values using Shodan or Censys, defenders can proactively identify new MuddyWater servers before they are used in attacks. This technique allowed Group-IB to map 63 IP addresses linked to MuddyWater — most of which were previously unknown to the security community. The three ETag hashes can be added to threat hunting playbooks for continuous monitoring.

Block the 63 documented IP addresses at the network perimeter and use the three ETag hashes (2aa6-5c939a3a79153, 2aa6-5b27e6e58988b, 2aa6-5c939a773f7a2) with Shodan or Censys to continuously hunt for new MuddyWater servers. Audit all installed remote management tools across your environment and maintain an approved allowlist — alert on any unauthorized installation of SimpleHelp, ScreenConnect, RemoteUtilities, or Syncro. Monitor for SimpleHelp service installation by non-standard parent processes, particularly those triggered by email clients. Alert on LNK shortcut files delivered inside archives that execute curl commands downloading VBScript payloads. Deploy email security controls to inspect links to OneDrive, Dropbox, and Onehub that deliver executables to recipients outside normal business workflows.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights