Evolving Threat: MuddyWater APT's Multi-National Cyber Espionage Activities
- Actor Motivations: Espionage,Exfiltration,Extortion
- Attack Vectors: Downloader,Dropper,Malicious Macro,Malware,Ransomware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The MuddyWater cyber-espionage group has been actively targeting Turkey, Armenia, and Pakistan in a sophisticated cyber campaign. Utilizing spearphishing techniques, they distributed malicious PDFs and Microsoft Office documents, often masquerading as official communications from Turkish ministries. These documents contained obfuscated PowerShell and Visual Basic scripts to establish persistence and download additional payloads. The campaign's tactics included living-off-the-land binaries, registry modifications for persistence, and the use of canary tokens for monitoring successful infections.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Ericson Telefonaktiebolaget LM Ericsson, commonly known as Ericsson, is a Swedish multinational networking and telecommunications company headquartered in Stockholm. Ericson has been targeted by MuddyWater with abusive purposes. | Verified |
| Case | The Ministry of Health of Turkey The Ministry of Health of Turkey has been targeted by MuddyWater as the main target. | Verified |
| Case | THE SCIENTIFIC AND TECHNOLOGICAL RESEARCH COUNCIL OF TÜRKİYE The Scientific and Technological Research Council of Türkiye (TÜBİTAK) is the leading agency for management, funding and conduct of research in Türkiye. THE SCIENTIFIC AND TECHNOLOGICAL RESEARCH COUNCIL OF TÜRKİYE has been targeted by MuddyWater as the main target. | Verified |
| Case | Turkey Ministry of Interior The Ministry of Interior or Ministry of the Interior or Interior Ministry is a government ministry of the Republic of Turkey, responsible for interior security affairs in Turkey. Turkey Ministry of Interior has been targeted by MuddyWater with unknown purposes. | Verified |
| Case | Viva MTS Viva-MTS is a telecommunications company in Armenia. Viva MTS has been targeted by MuddyWater as the main target. | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Telecommunication | Verified |
| Region | Armenia | Verified |
| Region | Pakistan | Verified |
| Region | Turkey | Verified |
Extracted IOCs
- canarytokens[.]com
- snapfile[.]org
- a.sara.1995a@gmail[.]com
- doctor.x.2020@gmail[.]com
- lillianwnwindrope@gmail[.]com
- sisterdoreencontreve@gmail[.]com
- ubuntoubunto1398@gmail[.]com
- ef4f0d9af47d737076923cfccfe01ba7
- 04d6ed9c6d4a37401ad3c586374f169b0aa8d609710bdcf5434d39e0fd4ed9bd
- 26ed7e89b3c5058836252e0a8ed9ec6b58f5f82a2e543bc6a97b3fd17ae3e4ec
- 28f2198f811bbd09be31ad51bac49ba0be5e46ebf5c617c49305bb7e274b198c
- 42aa5a474abc9efd3289833eab9e72a560fee48765b94b605fac469739a515c1
- 450302fb71d8e0e30c80f19cfe7fb7801b223754698cac0997eb3a3c8e440a48
- 5cdc7dd6162a8c791d50f5b2c5136d7ba3bf417104e6096bd4a2b76ea499a2f4
- 63e404011aeabb964ce63f467be29d678d0576bddb72124d491ab5565e1044cf
- 6910ddb58aee9a77e7bb9cadef9e6280a9b5b495edf0b6538cf8bdc1db8b1f4c
- 69e3a454c191ee38663112cf5358a54cca1229188087ed18e92bc9c59b014912
- 7dc49601fa6485c3a2cb1d519794bee004fb7fc0f3b37394a1aef6fceefec0c8
- 8b9be9e4d18c5fc71cd12dbfd60ea41eb88a07497e96faa2ba20fdc929b32c0b
- 8d6ed63f2ffa053a683810f5f96c76813cdca2e188f16d549e002b2f63cee001
- 8f255a1f2e17828a5b9205d6991e2c85c3320311da28048785262396cbc568c7
- 921b4520b75fcd0071944a483d738223b222ba101e70f2950fbfbc22afbdb5d0
- 9991b185c9e9732501e0c2bd841e32a4022f0735a0527150bc8e64ac363d409d
- a69fee382cf86f9e457e0688932cbd00671d0d5218f8043f1ee385278ee19c8c
- a8701fd6a5eb45e044f8bf150793f4189473dde46e0af8314652f6bf670c0a34
- aa72f1543d4a4e6ecbfc2da0167f5601c5c692bed73243cf01f616bc4af68afe
- b1e30cce6df16d83b82b751edca57aa17795d8d0cdd960ecee7d90832b0ee76c
- b4d0161ecab5a7847d325c88ce1a4fc2ca2e11fad0b77638b63ae1781c8b5793
- b726f4dd745891070f2e516d5d4e4f2f1ce0bf3ff685dc3800455383f342e54d
- c13cb1c9277324534075f807a3fcd24d0d3c024197c7437bf65db78f6a987f7a
- c9931382f844b61a002f83db1ae475953bbab449529be737df1eee8b3065f6eb
- cddd5514b7ed3d33ff8eaa16b7b71621ced857755246683e0d28c4650ea744bf
- d3ecc4137fc9a6d7418b4780864baf64cf7417d7badf463dff6ea48cd455915b
- d7de68febbbdb72ff820f6554afb464b5c204c434faa6ffe9b4daf6b691d535f
- d851badfcf3b3a8b4210bdb33948d0d1d918ec6bf0f1f85cbae6bb8feec7cd74
- d9de66497ad189d785d7535ab263e92ffad81df20b903c5e1d36859b4ed38b6d
- dc28b5e878152b5305b8d251019895caa56a7a95a68eccb89a6ecc41da8aadb9
- f6569039513e261ba9c70640e6eb8f59a0c72471889d3c0eaba51bdebb91d285
- fcdd38ff378605c66333429d9df2242fbce25a5f69f4d6d4c11d9613bcb409b0
- 137[.]74.131.16
- 149[.]202.242.84
- 172[.]245.81.135
- 185[.]118.164.165
- 185[.]118.164.195
- 185[.]118.164.213
- 185[.]118.167.120
- 185[.]141.27.211
- 5[.]199.133.149
- 7[.]236.212.22
- 88[.]119.170.124
- hxxp://137[.]74.131.16:443/
- hxxp://149[.]202.242.84:443/
- hxxp://172[.]245.81.135:10196/geq5p3afpasrk3pzterngusvcfqq9kz9/ef4f0d9af47d737076923cfccfe01ba7/layer[.]jpg
- hxxp://172[.]245.81.135:10196/geq5p3afpasrk3pzterngusvcfqq9kz9/pan-op/gallery[.]jpg
- hxxp://185[.]118.167.120/
- hxxp://185[.]141.27.211:443/
- hxxp://canarytokens[.]com/about/d3g23n4gdcrep20q3wzm153xn/index.html
- hxxp://canarytokens[.]com/tags/traffic/images/azp6ai8pg5aq0c619ur0qzi6h/
- hxxp://canarytokens[.]com/tags/traffic/images/azp6ai8pg5aq0c619ur0qzi6h/post.jsp
- hxxp://snapfile[.]org/756a12c43a0fb8d56fbf
- hxxps://snapfile[.]org/55e1c83e920bb7dc949c
- hxxps://snapfile[.]org/5bc3985cf17565a97dbd
- hxxps://snapfile[.]org/d/0c88a47c3160338bbb68
- hxxps://snapfile[.]org/d/c7817a35554e88572b7b
Tip: 64 related IOCs (11 IP, 2 domain, 14 URL, 5 email, 32 file hash) to this threat have been found.
Overlaps
Source: Deep Instinct - November 2023
Detection (one case): 63e404011aeabb964ce63f467be29d678d0576bddb72124d491ab5565e1044cf
Source: Deep Instinct - June 2023
Detection (one case): 137[.]74.131.16
Source: Group-IB - April 2023
Detection (two cases): 137[.]74.131.16, 149[.]202.242.84
Source: SOCRadar - January 2023
Detection (two cases): 5[.]199.133.149, 88[.]119.170.124
Source: NTT Security - May 2022
Detection (one case): 172[.]245.81.135
Source: Cisco Talos - March 2022
Detection (three cases): 185[.]118.164.195, 5[.]199.133.149, 88[.]119.170.124
Source: Picussecurity - March 2022
Detection (seven cases): 450302fb71d8e0e30c80f19cfe7fb7801b223754698cac0997eb3a3c8e440a48, 5cdc7dd6162a8c791d50f5b2c5136d7ba3bf417104e6096bd4a2b76ea499a2f4, 7dc49601fa6485c3a2cb1d519794bee004fb7fc0f3b37394a1aef6fceefec0c8, a69fee382cf86f9e457e0688932cbd00671d0d5218f8043f1ee385278ee19c8c, b1e30cce6df16d83b82b751edca57aa17795d8d0cdd960ecee7d90832b0ee76c, f6569039513e261ba9c70640e6eb8f59a0c72471889d3c0eaba51bdebb91d285, fcdd38ff378605c66333429d9df2242fbce25a5f69f4d6d4c11d9613bcb409b0
Source: CISA - February 2022
Detection (three cases): 5[.]199.133.149, 88[.]119.170.124, b1e30cce6df16d83b82b751edca57aa17795d8d0cdd960ecee7d90832b0ee76c
Source: Mandiant - February 2022
Detection (one case): 5[.]199.133.149
Source: CISA - February 2022
Detection (two cases): 5[.]199.133.149, 88[.]119.170.124
Source: Trakya University - September 2021
Detection (eight cases): 185[.]118.164.165, 185[.]118.164.195, 185[.]118.164.213, 185[.]118.167.120, a.sara.1995a@gmail[.]com, doctor.x.2020@gmail[.]com, lillianwnwindrope@gmail[.]com, ubuntoubunto1398@gmail[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
MuddyWater Cyber Campaign
A targeted cyber attack campaign was detected using fraudulent PDF documents to trick users into downloading malicious files. Once opened, these files dropped background scripts onto victim devices to establish unauthorized control and prepare for secondary payloads.
The attack was conducted by MuddyWater (also known as MERCURY or Static Kitten), an advanced threat group tied to Iran's Ministry of Intelligence and Security (MOIS). Active since at least 2017, the group routinely conducts state-sponsored operations worldwide.
The primary goals were espionage and intellectual property theft to provide political and economic advantages to the threat group's sponsors. Historically, the group has also deployed ransomware to disrupt target operations or cover their tracks.
This was a highly targeted cyber campaign rather than a mass automated attack. The threat actors specifically crafted localized lure documents in Turkish and other regional contexts to target designated high-value organizations.
The campaign targeted government agencies (such as Turkish research bodies), private entities, and telecommunications organizations in Turkey, Armenia, and Pakistan. These organizations are targeted because they possess sensitive political intelligence, proprietary technical data, and critical communications infrastructure.
Victims received emails with PDF attachments that instructed them to click a download link to view a document. Clicking the link retrieved a malicious file that secretly installed background persistence tools while opening a harmless-looking decoy document to keep the user unsuspecting.
Organizations should enforce strict email filtering rules, conduct regular phishing awareness training, and actively monitor network egress for suspicious script execution or known malicious network addresses. Maintaining and testing an incident response plan is also strongly advised.