Threats Feed|MuddyWater|Last Updated 26/08/2026|AuthorCertfa Radar|Publish Date31/01/2022

Evolving Threat: MuddyWater APT's Multi-National Cyber Espionage Activities

  • Actor Motivations: Espionage,Exfiltration,Extortion
  • Attack Vectors: Downloader,Dropper,Malicious Macro,Malware,Ransomware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The MuddyWater cyber-espionage group has been actively targeting Turkey, Armenia, and Pakistan in a sophisticated cyber campaign. Utilizing spearphishing techniques, they distributed malicious PDFs and Microsoft Office documents, often masquerading as official communications from Turkish ministries. These documents contained obfuscated PowerShell and Visual Basic scripts to establish persistence and download additional payloads. The campaign's tactics included living-off-the-land binaries, registry modifications for persistence, and the use of canary tokens for monitoring successful infections.

Detected Targets

TypeDescriptionConfidence
CaseEricson
Telefonaktiebolaget LM Ericsson, commonly known as Ericsson, is a Swedish multinational networking and telecommunications company headquartered in Stockholm. Ericson has been targeted by MuddyWater with abusive purposes.
Verified
CaseThe Ministry of Health of Turkey
The Ministry of Health of Turkey has been targeted by MuddyWater as the main target.
Verified
CaseTHE SCIENTIFIC AND TECHNOLOGICAL RESEARCH COUNCIL OF TÜRKİYE
The Scientific and Technological Research Council of Türkiye (TÜBİTAK) is the leading agency for management, funding and conduct of research in Türkiye. THE SCIENTIFIC AND TECHNOLOGICAL RESEARCH COUNCIL OF TÜRKİYE has been targeted by MuddyWater as the main target.
Verified
CaseTurkey Ministry of Interior
The Ministry of Interior or Ministry of the Interior or Interior Ministry is a government ministry of the Republic of Turkey, responsible for interior security affairs in Turkey. Turkey Ministry of Interior has been targeted by MuddyWater with unknown purposes.
Verified
CaseViva MTS
Viva-MTS is a telecommunications company in Armenia. Viva MTS has been targeted by MuddyWater as the main target.
Verified
SectorGovernment Agencies and Services
Verified
SectorTelecommunication
Verified
RegionArmenia
Verified
RegionPakistan
Verified
RegionTurkey
Verified

Extracted IOCs

  • canarytokens[.]com
  • snapfile[.]org
  • a.sara.1995a@gmail[.]com
  • doctor.x.2020@gmail[.]com
  • lillianwnwindrope@gmail[.]com
  • sisterdoreencontreve@gmail[.]com
  • ubuntoubunto1398@gmail[.]com
  • ef4f0d9af47d737076923cfccfe01ba7
  • 04d6ed9c6d4a37401ad3c586374f169b0aa8d609710bdcf5434d39e0fd4ed9bd
  • 26ed7e89b3c5058836252e0a8ed9ec6b58f5f82a2e543bc6a97b3fd17ae3e4ec
  • 28f2198f811bbd09be31ad51bac49ba0be5e46ebf5c617c49305bb7e274b198c
  • 42aa5a474abc9efd3289833eab9e72a560fee48765b94b605fac469739a515c1
  • 450302fb71d8e0e30c80f19cfe7fb7801b223754698cac0997eb3a3c8e440a48
  • 5cdc7dd6162a8c791d50f5b2c5136d7ba3bf417104e6096bd4a2b76ea499a2f4
  • 63e404011aeabb964ce63f467be29d678d0576bddb72124d491ab5565e1044cf
  • 6910ddb58aee9a77e7bb9cadef9e6280a9b5b495edf0b6538cf8bdc1db8b1f4c
  • 69e3a454c191ee38663112cf5358a54cca1229188087ed18e92bc9c59b014912
  • 7dc49601fa6485c3a2cb1d519794bee004fb7fc0f3b37394a1aef6fceefec0c8
  • 8b9be9e4d18c5fc71cd12dbfd60ea41eb88a07497e96faa2ba20fdc929b32c0b
  • 8d6ed63f2ffa053a683810f5f96c76813cdca2e188f16d549e002b2f63cee001
  • 8f255a1f2e17828a5b9205d6991e2c85c3320311da28048785262396cbc568c7
  • 921b4520b75fcd0071944a483d738223b222ba101e70f2950fbfbc22afbdb5d0
  • 9991b185c9e9732501e0c2bd841e32a4022f0735a0527150bc8e64ac363d409d
  • a69fee382cf86f9e457e0688932cbd00671d0d5218f8043f1ee385278ee19c8c
  • a8701fd6a5eb45e044f8bf150793f4189473dde46e0af8314652f6bf670c0a34
  • aa72f1543d4a4e6ecbfc2da0167f5601c5c692bed73243cf01f616bc4af68afe
  • b1e30cce6df16d83b82b751edca57aa17795d8d0cdd960ecee7d90832b0ee76c
  • b4d0161ecab5a7847d325c88ce1a4fc2ca2e11fad0b77638b63ae1781c8b5793
  • b726f4dd745891070f2e516d5d4e4f2f1ce0bf3ff685dc3800455383f342e54d
  • c13cb1c9277324534075f807a3fcd24d0d3c024197c7437bf65db78f6a987f7a
  • c9931382f844b61a002f83db1ae475953bbab449529be737df1eee8b3065f6eb
  • cddd5514b7ed3d33ff8eaa16b7b71621ced857755246683e0d28c4650ea744bf
  • d3ecc4137fc9a6d7418b4780864baf64cf7417d7badf463dff6ea48cd455915b
  • d7de68febbbdb72ff820f6554afb464b5c204c434faa6ffe9b4daf6b691d535f
  • d851badfcf3b3a8b4210bdb33948d0d1d918ec6bf0f1f85cbae6bb8feec7cd74
  • d9de66497ad189d785d7535ab263e92ffad81df20b903c5e1d36859b4ed38b6d
  • dc28b5e878152b5305b8d251019895caa56a7a95a68eccb89a6ecc41da8aadb9
  • f6569039513e261ba9c70640e6eb8f59a0c72471889d3c0eaba51bdebb91d285
  • fcdd38ff378605c66333429d9df2242fbce25a5f69f4d6d4c11d9613bcb409b0
  • 137[.]74.131.16
  • 149[.]202.242.84
  • 172[.]245.81.135
  • 185[.]118.164.165
  • 185[.]118.164.195
  • 185[.]118.164.213
  • 185[.]118.167.120
  • 185[.]141.27.211
  • 5[.]199.133.149
  • 7[.]236.212.22
  • 88[.]119.170.124
  • hxxp://137[.]74.131.16:443/
  • hxxp://149[.]202.242.84:443/
  • hxxp://172[.]245.81.135:10196/geq5p3afpasrk3pzterngusvcfqq9kz9/ef4f0d9af47d737076923cfccfe01ba7/layer[.]jpg
  • hxxp://172[.]245.81.135:10196/geq5p3afpasrk3pzterngusvcfqq9kz9/pan-op/gallery[.]jpg
  • hxxp://185[.]118.167.120/
  • hxxp://185[.]141.27.211:443/
  • hxxp://canarytokens[.]com/about/d3g23n4gdcrep20q3wzm153xn/index.html
  • hxxp://canarytokens[.]com/tags/traffic/images/azp6ai8pg5aq0c619ur0qzi6h/
  • hxxp://canarytokens[.]com/tags/traffic/images/azp6ai8pg5aq0c619ur0qzi6h/post.jsp
  • hxxp://snapfile[.]org/756a12c43a0fb8d56fbf
  • hxxps://snapfile[.]org/55e1c83e920bb7dc949c
  • hxxps://snapfile[.]org/5bc3985cf17565a97dbd
  • hxxps://snapfile[.]org/d/0c88a47c3160338bbb68
  • hxxps://snapfile[.]org/d/c7817a35554e88572b7b
download

Tip: 64 related IOCs (11 IP, 2 domain, 14 URL, 5 email, 32 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater's Shift to MuddyC2Go Framework Targets Jordan, Iraq, and Israel

Source: Deep Instinct - November 2023

Detection (one case): 63e404011aeabb964ce63f467be29d678d0576bddb72124d491ab5565e1044cf

MuddyWaterMuddyWater Upgrades: The Emergence of PhonyC2 Framework

Source: Deep Instinct - June 2023

Detection (one case): 137[.]74.131.16

MuddyWaterMuddyWater APT Uses Legitimate Remote Management Tool for Persistence

Source: Group-IB - April 2023

Detection (two cases): 137[.]74.131.16, 149[.]202.242.84

MuddyWaterMuddyWater APT: Iran's Cyber Espionage Across the Middle East and Beyond

Source: SOCRadar - January 2023

Detection (two cases): 5[.]199.133.149, 88[.]119.170.124

ENT-11ENT-11: Iranian APT Group's PowGoop Attacks Uncovered

Source: NTT Security - May 2022

Detection (one case): 172[.]245.81.135

MuddyWaterMuddyWater's Strategic Cyber Campaigns Across Turkey, Armenia, and Pakistan

Source: Cisco Talos - March 2022

Detection (three cases): 185[.]118.164.195, 5[.]199.133.149, 88[.]119.170.124

MuddyWaterMuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics

Source: Picussecurity - March 2022

Detection (seven cases): 450302fb71d8e0e30c80f19cfe7fb7801b223754698cac0997eb3a3c8e440a48, 5cdc7dd6162a8c791d50f5b2c5136d7ba3bf417104e6096bd4a2b76ea499a2f4, 7dc49601fa6485c3a2cb1d519794bee004fb7fc0f3b37394a1aef6fceefec0c8, a69fee382cf86f9e457e0688932cbd00671d0d5218f8043f1ee385278ee19c8c, b1e30cce6df16d83b82b751edca57aa17795d8d0cdd960ecee7d90832b0ee76c, f6569039513e261ba9c70640e6eb8f59a0c72471889d3c0eaba51bdebb91d285, fcdd38ff378605c66333429d9df2242fbce25a5f69f4d6d4c11d9613bcb409b0

MuddyWaterAnalysis of MuddyWater Malware Targeting Diverse International Sectors

Source: CISA - February 2022

Detection (three cases): 5[.]199.133.149, 88[.]119.170.124, b1e30cce6df16d83b82b751edca57aa17795d8d0cdd960ecee7d90832b0ee76c

UNC3313The Rise Of GRAMDOOR And STARWHALE In The Middle East: UNC3313 Suspected

Source: Mandiant - February 2022

Detection (one case): 5[.]199.133.149

MuddyWaterMuddyWater: Iranian APT Group Targets Global Networks Across Multiple Sectors

Source: CISA - February 2022

Detection (two cases): 5[.]199.133.149, 88[.]119.170.124

UnclassifiedCovid-19 Themed Phishing Attack Targets Organizations In Turkey

Source: Trakya University - September 2021

Detection (eight cases): 185[.]118.164.165, 185[.]118.164.195, 185[.]118.164.213, 185[.]118.167.120, a.sara.1995a@gmail[.]com, doctor.x.2020@gmail[.]com, lillianwnwindrope@gmail[.]com, ubuntoubunto1398@gmail[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

MuddyWater Cyber Campaign

A targeted cyber attack campaign was detected using fraudulent PDF documents to trick users into downloading malicious files. Once opened, these files dropped background scripts onto victim devices to establish unauthorized control and prepare for secondary payloads.

The attack was conducted by MuddyWater (also known as MERCURY or Static Kitten), an advanced threat group tied to Iran's Ministry of Intelligence and Security (MOIS). Active since at least 2017, the group routinely conducts state-sponsored operations worldwide.

The primary goals were espionage and intellectual property theft to provide political and economic advantages to the threat group's sponsors. Historically, the group has also deployed ransomware to disrupt target operations or cover their tracks.

This was a highly targeted cyber campaign rather than a mass automated attack. The threat actors specifically crafted localized lure documents in Turkish and other regional contexts to target designated high-value organizations.

The campaign targeted government agencies (such as Turkish research bodies), private entities, and telecommunications organizations in Turkey, Armenia, and Pakistan. These organizations are targeted because they possess sensitive political intelligence, proprietary technical data, and critical communications infrastructure.

Victims received emails with PDF attachments that instructed them to click a download link to view a document. Clicking the link retrieved a malicious file that secretly installed background persistence tools while opening a harmless-looking decoy document to keep the user unsuspecting.

Organizations should enforce strict email filtering rules, conduct regular phishing awareness training, and actively monitor network egress for suspicious script execution or known malicious network addresses. Maintaining and testing an incident response plan is also strongly advised.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights