Threats Feed|MuddyWater|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date22/11/2017

MuddyWater APT Focuses on Espionage in the Middle East: A Technical Analysis

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

ReaQta's November 2017 report documents MuddyWater, an Iranian-linked APT group active throughout 2017 targeting government, telecom, and oil sector organizations in the Middle East — primarily Iraq, Saudi Arabia, and UAE. The group's primary backdoor, POWERSTATS, is a PowerShell-based in-memory implant that exemplifies "living off the land" tradecraft: it leaves no binary on disk, uses legitimate system tools for execution, and leverages compromised third-party websites as proxy C2 relays to conceal the real C2 server. ReaQta first identified MuddyWater in September 2017 when it discovered an active campaign using GitHub for payload hosting, then observed the group rapidly pivot to Pastebin after GitHub blocked their account, and subsequently embed the payload directly in the macro document. The group shifted C2 servers four times between September and November 2017 in response to public disclosures. Following Saudi Arabia's National Cybersecurity Center advisory in November 2017, MuddyWater added Koadic (a JScript RAT) and Meterpreter as secondary payloads. Key findings include: 10% of endpoints at a major Iraqi telecom provider were infected; 85% of victims ran Windows workstations with the remaining 15% being servers; operators showed high activity on Iraqi, Saudi, and UAE victims while largely ignoring Pakistani infections despite Pakistan having the most raw infections; attack hours were consistent with an Iranian work schedule. IOCs include 7 C2 IPs, 54 domains (compromised proxy sites), 74 C2 URLs, and 17 file hashes.

Detected Targets

TypeDescriptionConfidence
CaseIraqi National Intelligence Service
The Iraqi National Intelligence Service is an intelligence agency of the Iraqi government that was created in April 2004 on the transitional authority of the Coalition Provisional Authority, following the American invasion of Iraq a year prior. Iraqi National Intelligence Service has been targeted by MuddyWater with abusive purposes.
Verified
CaseNational Security Agency (NSA)
The National Security Agency is a national-level intelligence agency of the United States Department of Defense, under the authority of the Director of National Intelligence. National Security Agency (NSA) has been targeted by MuddyWater with abusive purposes.
Verified
CasePakistan Federal Investigation Agency
Federal Investigation Agency is the premier agency of Pakistan at national level to investigate federal crimes. Pakistan Federal Investigation Agency has been targeted by MuddyWater with abusive purposes.
Verified
CaseSaudi Arabia Ministry of Interior
The Ministry of Interior is one of the governmental bodies of Saudi Arabia responsible for national security, naturalization, immigration, and customs in Saudi Arabia. Saudi Arabia Ministry of Interior has been targeted by MuddyWater with abusive purposes.
Verified
SectorGovernment Agencies and Services
Verified
SectorTelecommunication
Verified
SectorUtilities
Verified
RegionEgypt
Verified
RegionIran
Verified
RegionIraq
Verified
RegionIsrael
Verified
RegionJordan
Verified
RegionLebanon
Verified
RegionPakistan
Verified
RegionSaudi Arabia
Verified
RegionTunisia
Verified
RegionTurkey
Verified
RegionUnited Arab Emirates
Verified
RegionUnited Kingdom
Verified
RegionUnited States
Verified

Extracted IOCs

  • arbiogaz[.]com
  • arch-tech[.]net
  • bangortalk.org[.]uk
  • bikekaidee[.]com
  • camco.com[.]pk
  • cgss.com[.]pk
  • feribschat[.]eu
  • fifacare55[.]com
  • ghanaconsulate.com[.]pk
  • heartmade[.]ae
  • itcdubai[.]net
  • larsson-elevator[.]com
  • magical-energy[.]com
  • mainandstrand[.]com
  • mhtevents[.]com
  • ohofifa[.]com
  • projac.co[.]uk
  • romix-group[.]com
  • skepticalscience[.]com
  • suliparwarda[.]com
  • taxconsultantsdubai[.]ae
  • teeyaipakin[.]com
  • tmclub[.]eu
  • wallpapercase[.]com
  • whiver[.]in
  • wmg-global[.]com
  • azmwn.suliparwarda[.]com
  • best2.thebestconference[.]org
  • coa.inducks[.]org
  • kale.alfa-bilisim[.]com
  • school.suliparwarda[.]com
  • watyanagr.nfe.go[.]th
  • www.4seasonrentacar[.]com
  • www.akhtaredanesh[.]com
  • www.amarsarkar[.]com
  • www.arcadecreative[.]com
  • www.armaholic[.]com
  • www.asan-max[.]com
  • www.autotrans[.]hr
  • www.dafc.co[.]uk
  • www.eapa[.]org
  • www.elev8tor[.]com
  • www.jdarchs[.]com
  • www.kunkrooann[.]com
  • www.mackellarscreenworks[.]com
  • www.mitegen[.]com
  • www.nigelwhitfield[.]com
  • www.pomegranates[.]org
  • www.ridefox[.]com
  • www.shapingtomorrowsworld[.]org
  • www.spearhead-training[.]com
  • www.vanessajackson.co[.]uk
  • www.yaran[.]co
  • www.ztm.waw[.]pl
  • 1206ae0a9dd740e5c14ce842d9a93829cfe0db6f5bb8d8cf164f6d0abcb3541d
  • 16bcb6cc38347a722bb7682799e9d9da40788e3ca15f29e46b475efe869d0a04
  • 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1
  • 40a6b4c6746e37d0c5ecb801e7656c9941f4839f94d8f4cd61eaf2b812feaabe
  • 4121db476b66241610985350b825b9f1680d0171ab01a52b5ffcb56481521e44
  • 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f
  • 917a6c816684f22934e2998f43633179e14dcc2e609c6931dd2fc36098c48028
  • 9c5404db9652b3862e40ba0642b05030eef4d896e30c497be5aa4073974e1c08
  • a0abec361411cb11e01337939013bad1f54ad5865c73604a1b360d68ddfbd96a
  • a6673c6d52dd5361afd96f8143b88810812daa97004f69661da625aaaba9363b
  • a71c7451934830c6796dff4a937811aaf0dd519b756ff99b3e66d91a049ca801
  • b2c10621c9c901f0f692cae0306baa840105231f35e6ec36e41b88eebd46df4c
  • c8fa6056145ce2662d673593faa8162734eefa04ec9a51f6d94e8df8a0c5675b
  • de6ce9b75f4523a5b235f90fa00027be5920c97a972ad6cb2311953446c81e1d
  • e22f21d486631d813c4ad77b1c106c621ec95bf002c19f4cb979312f198266f5
  • e5a60c8f90e846fe22b3b0ec3675038d214cacd1564d6d2b1add9b9c54bc601b
  • fe27abcbad72ede7fd668cfe2f9938d42248133b0aa068c9196a4766eaffc18e
  • 104[.]237.233.38
  • 106[.]187.38.21
  • 144[.]76.109.88
  • 148[.]251.204.131
  • 78[.]129.139.134
  • 78[.]129.139.147
  • 88[.]99.17.148
  • hxxp://104[.]237.233.38:9999
  • hxxp://106[.]187.38.21/short_qr/work[.]php?c=
  • hxxp://148[.]251.204.131:8060
  • hxxp://78[.]129.139.134:9999
  • hxxp://78[.]129.139.147:8060
  • hxxp://arbiogaz[.]com/upload/work.php?c=
  • hxxp://arch-tech[.]net/components/com_layer_slider/senditem.php?c=
  • hxxp://azmwn.suliparwarda[.]com/wp-content/plugins/wpdatatables/panda.php?c=
  • hxxp://azmwn.suliparwarda[.]com/wp-content/themes/twentyfifteen/logs.php?c=
  • hxxp://bangortalk.org[.]uk/speakers.php?c=
  • hxxp://best2.thebestconference[.]org/ccb/browse_cat.php?c=
  • hxxp://bikekaidee[.]com/admin/404.php?c=
  • hxxp://camco.com[.]pk/controls/data.aspx?c=
  • hxxp://cgss.com[.]pk/data.aspx?c=
  • hxxp://feribschat[.]eu/logs.php?c=
  • hxxp://fifacare55[.]com/404.php?c=
  • hxxp://ghanaconsulate.com[.]pk/data.aspx?c=
  • hxxp://heartmade[.]ae/plugins/content/contact/senditem.php?c=
  • hxxp://itcdubai[.]net/action/contact_gtc.php?c=
  • hxxp://kale.alfa-bilisim[.]com/banka/3d/data.aspx?c=
  • hxxp://kale.alfa-bilisim[.]com/content/data.aspx?c=
  • hxxp://larsson-elevator[.]com/plugins/xmap/com_k2/com.php?c=
  • hxxp://magical-energy[.]com/css.aspx?c=
  • hxxp://magical-energy[.]com/css/css.aspx?c=
  • hxxp://mainandstrand[.]com/work.php?c=
  • hxxp://ohofifa[.]com/wp-content/themes/newspaper/mobile/includes/404.php?c=
  • hxxp://ohofifa[.]com/wp-content/themes/newspaper/mobile/work.php?c=
  • hxxp://projac.co[.]uk/senditem.php?c=
  • hxxp://romix-group[.]com/modules/mod_wrapper/senditem.php?c=
  • hxxps://78[.]129.139.134:6643
  • hxxp://school.suliparwarda[.]com/components/com_akeeba/work.php?c=
  • hxxp://school.suliparwarda[.]com/plugins/editors/codemirror/work.php?c=
  • hxxps://coa.inducks[.]org/publication.php?c=
  • hxxps://mhtevents[.]com/account.php?c=
  • hxxps://skepticalscience[.]com/graphics.php?c=
  • hxxp://suliparwarda[.]com/wp-content/plugins/entry-views/work.php?c=
  • hxxp://suliparwarda[.]com/wp-content/themes/twentyfifteen/work.php?c=
  • hxxps://wallpapercase[.]com/wp-content/themes/twentyfifteen/logs.php?c=
  • hxxps://wallpapercase[.]com/wp-includes/customize/logs.php?c=
  • hxxps://www.spearhead-training[.]com/action/point2.php?c=
  • hxxps://www.spearhead-training[.]com//html/power.php?c=
  • hxxps://www.spearhead-training[.]com/work.php?c=
  • hxxp://taxconsultantsdubai[.]ae/wp-content/themes/config.php?c=
  • hxxp://teeyaipakin[.]com/wp-content/plugins/all-in-one-seo-pack/404.php?c=
  • hxxp://tmclub[.]eu/clubdata.php?c=
  • hxxp://watyanagr.nfe.go[.]th/e-office/lib/work.php?c=
  • hxxp://watyanagr.nfe.go[.]th/watyanagr/power.php?c=
  • hxxp://whiver[.]in/power.php?c=
  • hxxp://www.4seasonrentacar[.]com/viewsure/data.aspx?c=
  • hxxp://www.akhtaredanesh[.]com/d/file/sym/work.php?c=
  • hxxp://www.akhtaredanesh[.]com/d/oschool/power.php?c=
  • hxxp://www.amarsarkar[.]com/webadmin/404.php?c=
  • hxxp://www.amarsarkar[.]com/webadmin/inc/404.php?c=
  • hxxp://www.arcadecreative[.]com/work.php?c=
  • hxxp://www.armaholic[.]com/list.php?c=
  • hxxp://www.asan-max[.]com/files/articles/css.aspx?c=
  • hxxp://www.asan-max[.]com/files/articles/large/css.aspx?c=
  • hxxp://www.autotrans[.]hr/index.php?c=
  • hxxp://www.dafc.co[.]uk/news.php?c=
  • hxxp://www.eapa[.]org/asphalt.php?c=
  • hxxp://www.elev8tor[.]com/show-work.php?c=
  • hxxp://www.jdarchs[.]com/work.php?c=
  • hxxp://www.kunkrooann[.]com/inc/work.php?c=
  • hxxp://www.mackellarscreenworks[.]com/work.php?c=
  • hxxp://www.mitegen[.]com/mic_catalog.php?c=
  • hxxp://www.nigelwhitfield[.]com/v2/work.php?c=
  • hxxp://www.pomegranates[.]org/index.php?c=
  • hxxp://www.ridefox[.]com/content.php?c=
  • hxxp://www.shapingtomorrowsworld[.]org/category.php?c=
  • hxxp://www.vanessajackson.co[.]uk/work.php?c=
  • hxxp://www.wmg-global[.]com/wp-content/wp_fast_cache/wmg-global.com/senditem.php?c=
  • hxxp://www.yaran[.]co//wp-content/plugins/so-masonry/logs.php?c=
  • hxxp://www.yaran[.]co/wp-includes/widgets/logs.php?c=
  • hxxp://www.ztm.waw[.]pl/pop.php?c=
download

Tip: 152 related IOCs (7 IP, 54 domain, 74 URL, 0 email, 17 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics

Source: Picussecurity - March 2022

Detection (six cases): 16bcb6cc38347a722bb7682799e9d9da40788e3ca15f29e46b475efe869d0a04, 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1, 40a6b4c6746e37d0c5ecb801e7656c9941f4839f94d8f4cd61eaf2b812feaabe, 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f, b2c10621c9c901f0f692cae0306baa840105231f35e6ec36e41b88eebd46df4c, de6ce9b75f4523a5b235f90fa00027be5920c97a972ad6cb2311953446c81e1d

MuddyWaterMuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

Source: Trend Micro - June 2019

Detection (three cases): 104[.]237.233.38, 78[.]129.139.134, 88[.]99.17.148

MuddyWaterDecoding MuddyWater: Inside the APT's Advanced Toolset and Deception Tactics

Source: Kaspersky - April 2019

Detection (two cases): 104[.]237.233.38, 78[.]129.139.134

MuddyWaterMuddyWater Targets Middle East Using POWERSTATS Backdoor

Source: Unit 42 - Palo Alto Networks - November 2017

Detection (100 cases): 106[.]187.38.21, 144[.]76.109.88, 148[.]251.204.131, hxxp://106[.]187.38.21/short_qr/work[.]php?c=, hxxp://arbiogaz[.]com/upload/work.php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/plugins/wpdatatables/panda.php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxp://bangortalk.org[.]uk/speakers.php?c=, hxxp://best2.thebestconference[.]org/ccb/browse_cat.php?c=, hxxp://camco.com[.]pk/controls/data.aspx?c=, hxxp://cgss.com[.]pk/data.aspx?c=, hxxp://feribschat[.]eu/logs.php?c=, hxxp://ghanaconsulate.com[.]pk/data.aspx?c=, hxxp://magical-energy[.]com/css.aspx?c=, hxxp://magical-energy[.]com/css/css.aspx?c=, hxxp://mainandstrand[.]com/work.php?c=, hxxp://school.suliparwarda[.]com/components/com_akeeba/work.php?c=, hxxp://school.suliparwarda[.]com/plugins/editors/codemirror/work.php?c=, hxxp://suliparwarda[.]com/wp-content/plugins/entry-views/work.php?c=, hxxp://suliparwarda[.]com/wp-content/themes/twentyfifteen/work.php?c=, hxxp://tmclub[.]eu/clubdata.php?c=, hxxp://watyanagr.nfe.go[.]th/e-office/lib/work.php?c=, hxxp://watyanagr.nfe.go[.]th/watyanagr/power.php?c=, hxxp://whiver[.]in/power.php?c=, hxxp://www.4seasonrentacar[.]com/viewsure/data.aspx?c=, hxxp://www.akhtaredanesh[.]com/d/file/sym/work.php?c=, hxxp://www.akhtaredanesh[.]com/d/oschool/power.php?c=, hxxp://www.arcadecreative[.]com/work.php?c=, hxxp://www.armaholic[.]com/list.php?c=, hxxp://www.asan-max[.]com/files/articles/css.aspx?c=, hxxp://www.asan-max[.]com/files/articles/large/css.aspx?c=, hxxp://www.autotrans[.]hr/index.php?c=, hxxp://www.dafc.co[.]uk/news.php?c=, hxxp://www.eapa[.]org/asphalt.php?c=, hxxp://www.elev8tor[.]com/show-work.php?c=, hxxp://www.jdarchs[.]com/work.php?c=, hxxp://www.kunkrooann[.]com/inc/work.php?c=, hxxp://www.mackellarscreenworks[.]com/work.php?c=, hxxp://www.mitegen[.]com/mic_catalog.php?c=, hxxp://www.nigelwhitfield[.]com/v2/work.php?c=, hxxp://www.pomegranates[.]org/index.php?c=, hxxp://www.ridefox[.]com/content.php?c=, hxxp://www.shapingtomorrowsworld[.]org/category.php?c=, hxxp://www.vanessajackson.co[.]uk/work.php?c=, hxxp://www.yaran[.]co//wp-content/plugins/so-masonry/logs.php?c=, hxxp://www.yaran[.]co/wp-includes/widgets/logs.php?c=, hxxp://www.ztm.waw[.]pl/pop.php?c=, hxxps://coa.inducks[.]org/publication.php?c=, hxxps://mhtevents[.]com/account.php?c=, hxxps://skepticalscience[.]com/graphics.php?c=, hxxps://wallpapercase[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxps://wallpapercase[.]com/wp-includes/customize/logs.php?c=, hxxps://www.spearhead-training[.]com//html/power.php?c=, hxxps://www.spearhead-training[.]com/work.php?c=, 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1, 40a6b4c6746e37d0c5ecb801e7656c9941f4839f94d8f4cd61eaf2b812feaabe, 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f, 917a6c816684f22934e2998f43633179e14dcc2e609c6931dd2fc36098c48028, a6673c6d52dd5361afd96f8143b88810812daa97004f69661da625aaaba9363b, de6ce9b75f4523a5b235f90fa00027be5920c97a972ad6cb2311953446c81e1d, arbiogaz[.]com, azmwn.suliparwarda[.]com, bangortalk.org[.]uk, best2.thebestconference[.]org, camco.com[.]pk, cgss.com[.]pk, coa.inducks[.]org, feribschat[.]eu, ghanaconsulate.com[.]pk, magical-energy[.]com, mainandstrand[.]com, mhtevents[.]com, school.suliparwarda[.]com, skepticalscience[.]com, suliparwarda[.]com, tmclub[.]eu, wallpapercase[.]com, watyanagr.nfe.go[.]th, whiver[.]in, www.4seasonrentacar[.]com, www.akhtaredanesh[.]com, www.arcadecreative[.]com, www.armaholic[.]com, www.asan-max[.]com, www.autotrans[.]hr, www.dafc.co[.]uk, www.eapa[.]org, www.elev8tor[.]com, www.jdarchs[.]com, www.kunkrooann[.]com, www.mackellarscreenworks[.]com, www.mitegen[.]com, www.nigelwhitfield[.]com, www.pomegranates[.]org, www.ridefox[.]com, www.shapingtomorrowsworld[.]org, www.spearhead-training[.]com, www.vanessajackson.co[.]uk, www.yaran[.]co, www.ztm.waw[.]pl

MuddyWaterContinuing MuddyWater Phishing Campaign Targets Middle East and Pakistan

Source: Security 0wnage - November 2017

Detection (82 cases): 106[.]187.38.21, 148[.]251.204.131, hxxp://106[.]187.38.21/short_qr/work[.]php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/plugins/wpdatatables/panda.php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxp://bangortalk.org[.]uk/speakers.php?c=, hxxp://best2.thebestconference[.]org/ccb/browse_cat.php?c=, hxxp://feribschat[.]eu/logs.php?c=, hxxp://magical-energy[.]com/css.aspx?c=, hxxp://magical-energy[.]com/css/css.aspx?c=, hxxp://mainandstrand[.]com/work.php?c=, hxxp://school.suliparwarda[.]com/components/com_akeeba/work.php?c=, hxxp://school.suliparwarda[.]com/plugins/editors/codemirror/work.php?c=, hxxp://suliparwarda[.]com/wp-content/plugins/entry-views/work.php?c=, hxxp://suliparwarda[.]com/wp-content/themes/twentyfifteen/work.php?c=, hxxp://tmclub[.]eu/clubdata.php?c=, hxxp://watyanagr.nfe.go[.]th/watyanagr/power.php?c=, hxxp://whiver[.]in/power.php?c=, hxxp://www.akhtaredanesh[.]com/d/file/sym/work.php?c=, hxxp://www.akhtaredanesh[.]com/d/oschool/power.php?c=, hxxp://www.arcadecreative[.]com/work.php?c=, hxxp://www.armaholic[.]com/list.php?c=, hxxp://www.asan-max[.]com/files/articles/css.aspx?c=, hxxp://www.asan-max[.]com/files/articles/large/css.aspx?c=, hxxp://www.autotrans[.]hr/index.php?c=, hxxp://www.dafc.co[.]uk/news.php?c=, hxxp://www.eapa[.]org/asphalt.php?c=, hxxp://www.elev8tor[.]com/show-work.php?c=, hxxp://www.jdarchs[.]com/work.php?c=, hxxp://www.kunkrooann[.]com/inc/work.php?c=, hxxp://www.mackellarscreenworks[.]com/work.php?c=, hxxp://www.mitegen[.]com/mic_catalog.php?c=, hxxp://www.nigelwhitfield[.]com/v2/work.php?c=, hxxp://www.pomegranates[.]org/index.php?c=, hxxp://www.ridefox[.]com/content.php?c=, hxxp://www.shapingtomorrowsworld[.]org/category.php?c=, hxxp://www.vanessajackson.co[.]uk/work.php?c=, hxxp://www.yaran[.]co//wp-content/plugins/so-masonry/logs.php?c=, hxxp://www.yaran[.]co/wp-includes/widgets/logs.php?c=, hxxp://www.ztm.waw[.]pl/pop.php?c=, hxxps://coa.inducks[.]org/publication.php?c=, hxxps://mhtevents[.]com/account.php?c=, hxxps://skepticalscience[.]com/graphics.php?c=, hxxps://wallpapercase[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxps://wallpapercase[.]com/wp-includes/customize/logs.php?c=, hxxps://www.spearhead-training[.]com//html/power.php?c=, hxxps://www.spearhead-training[.]com/work.php?c=, azmwn.suliparwarda[.]com, bangortalk.org[.]uk, best2.thebestconference[.]org, coa.inducks[.]org, feribschat[.]eu, magical-energy[.]com, mainandstrand[.]com, mhtevents[.]com, school.suliparwarda[.]com, skepticalscience[.]com, suliparwarda[.]com, tmclub[.]eu, wallpapercase[.]com, watyanagr.nfe.go[.]th, whiver[.]in, www.akhtaredanesh[.]com, www.arcadecreative[.]com, www.armaholic[.]com, www.asan-max[.]com, www.autotrans[.]hr, www.dafc.co[.]uk, www.eapa[.]org, www.elev8tor[.]com, www.jdarchs[.]com, www.kunkrooann[.]com, www.mackellarscreenworks[.]com, www.mitegen[.]com, www.nigelwhitfield[.]com, www.pomegranates[.]org, www.ridefox[.]com, www.shapingtomorrowsworld[.]org, www.spearhead-training[.]com, www.vanessajackson.co[.]uk, www.yaran[.]co, www.ztm.waw[.]pl

MuddyWaterUnveiling MuddyWater Phishing Campaign: Middle Eastern Governments in the Crosshairs

Source: Security 0wnage - October 2017

Detection (five cases): 144[.]76.109.88, 148[.]251.204.131, 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1, 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f, 917a6c816684f22934e2998f43633179e14dcc2e609c6931dd2fc36098c48028

UnclassifiedSaudi Arabian Government Hit by Stealthy Macro Malware

Source: Malwarebytes - September 2017

Detection (nine cases): 144[.]76.109.88, arch-tech[.]net, heartmade[.]ae, itcdubai[.]net, larsson-elevator[.]com, projac.co[.]uk, romix-group[.]com, taxconsultantsdubai[.]ae, wmg-global[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions About MuddyWater's 2017 Middle East Espionage Campaign

MuddyWater, an Iranian-linked APT group, conducted a sustained "living off the land" espionage campaign throughout 2017 targeting government agencies, telecom providers, and oil companies in Iraq, Saudi Arabia, and UAE. The group delivered its primary backdoor — POWERSTATS, a PowerShell-based implant — through malicious Office macro documents, and used a network of compromised legitimate websites as proxy relays to hide its real C2 server. ReaQta made the first public disclosure of MuddyWater in September 2017, and the group adapted rapidly to each publication, shifting infrastructure and expanding its toolset through November 2017.

The campaign is attributed to MuddyWater, a threat group assessed to operate on behalf of the Iranian government or to be an Iranian criminal organization engaged in espionage. ReaQta's analysis identified Iran as the likely originating country based on operator working hours consistent with Iranian time zones, the geographic focus on Iran's regional rivals, and the nature of the targeted sectors. MuddyWater is also tracked as TEMP.Zagros, Static Kitten, and Seedworm, and has since been formally attributed by the US Cyber Command and CISA to Iranian intelligence.

The primary goal was intelligence collection. MuddyWater operators showed strong interest in government agencies, telecommunications providers, and oil companies in Iraq, Saudi Arabia, and UAE — sectors of direct strategic value to Iran. The deeply compromised Iraqi telecom provider (10% of endpoints infected) and the high operator activity on Saudi and UAE victims compared to Pakistani victims despite lower infection counts indicates deliberate targeting of high-value intelligence sources rather than opportunistic spreading. ReaQta derived the espionage motivation from analysis of the backdoor's behaviors and the data it collected.

Despite Pakistan having the most raw infections, the real primary targets were Iraq, Saudi Arabia, and UAE. In Iraq, a major telecom provider had 10% of its endpoints compromised with POWERSTATS — an unusually deep penetration. Named victims include the Iraqi National Intelligence Service, Saudi Arabia's Ministry of Interior, Pakistan's Federal Investigation Agency, and the National Security Agency of an unnamed country. The broader victim set included governments, telecom companies, and oil infrastructure across the Middle East, with additional infections in Turkey, Jordan, Lebanon, Israel, Egypt, Tunisia, the UK, and the US — primarily travelers and diaspora from the primary target countries.

Iraq, Saudi Arabia, and UAE are all direct strategic rivals or regional competitors of Iran. Iraqi government and telecom infrastructure holds intelligence on Iranian border security, military movements, and diplomatic communications. Saudi Arabia is Iran's primary geopolitical adversary with control over significant oil production competing with Iran's. UAE serves as a major financial and logistics hub that Iran monitors for sanctions evasion and regional intelligence. The oil platform compromise also reflects interest in energy infrastructure that Iran monitors for pricing, production, and geopolitical leverage.

MuddyWater delivered POWERSTATS via spearphishing emails carrying Office documents with embedded VBA macros. When the victim opened the document and enabled macros, the macro executed PowerShell commands entirely in memory — no binary was written to disk, keeping the forensic footprint minimal. The PowerShell backdoor connected to one of many compromised legitimate websites acting as a proxy relay, which forwarded traffic to the real C2 server. This proxy layer made blocking and attribution significantly harder. Payload hosting evolved from GitHub to Pastebin to embedded macros across the campaign, and by November 2017 the group also deployed Koadic (a JScript RAT) and Meterpreter on selected high-value victims for additional post-exploitation capability.

MuddyWater's rapid adaptation to each public disclosure was notable. When ReaQta published the first report and GitHub blocked the payload repository, the group shifted to Pastebin within hours. When MalwareBytes published analysis referencing the Pastebin C2, the group changed its C2 IP the same day and moved to embedding payloads directly in documents. When Palo Alto and Saudi Arabia's NCSC published advisories, MuddyWater expanded its toolset with Koadic and Meterpreter within six days. The group cycled through four different C2 IPs in under two months. This speed of adaptation — all without missing significant operational tempo — reflects a well-resourced, actively managed operation rather than opportunistic malware distribution.

Block outbound connections to the 7 documented C2 IPs and monitor the 54 compromised proxy domains, but note that the proxy-relay C2 architecture makes IP and domain blocking insufficient on its own — behavioral detection is required. Disable VBA macros in Office documents from external sources and block macro-enabled Office attachments at the email gateway. Enable PowerShell Script Block Logging and AMSI to capture obfuscated POWERSTATS at runtime, since the malware leaves no binary on disk and cannot be detected through file scanning alone. Alert on PowerShell processes spawned by Office applications that make outbound HTTP connections or modify Registry Run keys. Monitor scheduled task creation by script processes and alert on any in-memory PowerShell sessions establishing external connections — the primary behavioral signature of POWERSTATS.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights