MuddyWater APT Focuses on Espionage in the Middle East: A Technical Analysis
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malware,RAT,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
ReaQta's November 2017 report documents MuddyWater, an Iranian-linked APT group active throughout 2017 targeting government, telecom, and oil sector organizations in the Middle East — primarily Iraq, Saudi Arabia, and UAE. The group's primary backdoor, POWERSTATS, is a PowerShell-based in-memory implant that exemplifies "living off the land" tradecraft: it leaves no binary on disk, uses legitimate system tools for execution, and leverages compromised third-party websites as proxy C2 relays to conceal the real C2 server. ReaQta first identified MuddyWater in September 2017 when it discovered an active campaign using GitHub for payload hosting, then observed the group rapidly pivot to Pastebin after GitHub blocked their account, and subsequently embed the payload directly in the macro document. The group shifted C2 servers four times between September and November 2017 in response to public disclosures. Following Saudi Arabia's National Cybersecurity Center advisory in November 2017, MuddyWater added Koadic (a JScript RAT) and Meterpreter as secondary payloads. Key findings include: 10% of endpoints at a major Iraqi telecom provider were infected; 85% of victims ran Windows workstations with the remaining 15% being servers; operators showed high activity on Iraqi, Saudi, and UAE victims while largely ignoring Pakistani infections despite Pakistan having the most raw infections; attack hours were consistent with an Iranian work schedule. IOCs include 7 C2 IPs, 54 domains (compromised proxy sites), 74 C2 URLs, and 17 file hashes.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | Iraqi National Intelligence Service The Iraqi National Intelligence Service is an intelligence agency of the Iraqi government that was created in April 2004 on the transitional authority of the Coalition Provisional Authority, following the American invasion of Iraq a year prior. Iraqi National Intelligence Service has been targeted by MuddyWater with abusive purposes. | Verified |
| Case | National Security Agency (NSA) The National Security Agency is a national-level intelligence agency of the United States Department of Defense, under the authority of the Director of National Intelligence. National Security Agency (NSA) has been targeted by MuddyWater with abusive purposes. | Verified |
| Case | Pakistan Federal Investigation Agency Federal Investigation Agency is the premier agency of Pakistan at national level to investigate federal crimes. Pakistan Federal Investigation Agency has been targeted by MuddyWater with abusive purposes. | Verified |
| Case | Saudi Arabia Ministry of Interior The Ministry of Interior is one of the governmental bodies of Saudi Arabia responsible for national security, naturalization, immigration, and customs in Saudi Arabia. Saudi Arabia Ministry of Interior has been targeted by MuddyWater with abusive purposes. | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Telecommunication | Verified |
| Sector | Utilities | Verified |
| Region | Egypt | Verified |
| Region | Iran | Verified |
| Region | Iraq | Verified |
| Region | Israel | Verified |
| Region | Jordan | Verified |
| Region | Lebanon | Verified |
| Region | Pakistan | Verified |
| Region | Saudi Arabia | Verified |
| Region | Tunisia | Verified |
| Region | Turkey | Verified |
| Region | United Arab Emirates | Verified |
| Region | United Kingdom | Verified |
| Region | United States | Verified |
Extracted IOCs
- arbiogaz[.]com
- arch-tech[.]net
- bangortalk.org[.]uk
- bikekaidee[.]com
- camco.com[.]pk
- cgss.com[.]pk
- feribschat[.]eu
- fifacare55[.]com
- ghanaconsulate.com[.]pk
- heartmade[.]ae
- itcdubai[.]net
- larsson-elevator[.]com
- magical-energy[.]com
- mainandstrand[.]com
- mhtevents[.]com
- ohofifa[.]com
- projac.co[.]uk
- romix-group[.]com
- skepticalscience[.]com
- suliparwarda[.]com
- taxconsultantsdubai[.]ae
- teeyaipakin[.]com
- tmclub[.]eu
- wallpapercase[.]com
- whiver[.]in
- wmg-global[.]com
- azmwn.suliparwarda[.]com
- best2.thebestconference[.]org
- coa.inducks[.]org
- kale.alfa-bilisim[.]com
- school.suliparwarda[.]com
- watyanagr.nfe.go[.]th
- www.4seasonrentacar[.]com
- www.akhtaredanesh[.]com
- www.amarsarkar[.]com
- www.arcadecreative[.]com
- www.armaholic[.]com
- www.asan-max[.]com
- www.autotrans[.]hr
- www.dafc.co[.]uk
- www.eapa[.]org
- www.elev8tor[.]com
- www.jdarchs[.]com
- www.kunkrooann[.]com
- www.mackellarscreenworks[.]com
- www.mitegen[.]com
- www.nigelwhitfield[.]com
- www.pomegranates[.]org
- www.ridefox[.]com
- www.shapingtomorrowsworld[.]org
- www.spearhead-training[.]com
- www.vanessajackson.co[.]uk
- www.yaran[.]co
- www.ztm.waw[.]pl
- 1206ae0a9dd740e5c14ce842d9a93829cfe0db6f5bb8d8cf164f6d0abcb3541d
- 16bcb6cc38347a722bb7682799e9d9da40788e3ca15f29e46b475efe869d0a04
- 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1
- 40a6b4c6746e37d0c5ecb801e7656c9941f4839f94d8f4cd61eaf2b812feaabe
- 4121db476b66241610985350b825b9f1680d0171ab01a52b5ffcb56481521e44
- 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f
- 917a6c816684f22934e2998f43633179e14dcc2e609c6931dd2fc36098c48028
- 9c5404db9652b3862e40ba0642b05030eef4d896e30c497be5aa4073974e1c08
- a0abec361411cb11e01337939013bad1f54ad5865c73604a1b360d68ddfbd96a
- a6673c6d52dd5361afd96f8143b88810812daa97004f69661da625aaaba9363b
- a71c7451934830c6796dff4a937811aaf0dd519b756ff99b3e66d91a049ca801
- b2c10621c9c901f0f692cae0306baa840105231f35e6ec36e41b88eebd46df4c
- c8fa6056145ce2662d673593faa8162734eefa04ec9a51f6d94e8df8a0c5675b
- de6ce9b75f4523a5b235f90fa00027be5920c97a972ad6cb2311953446c81e1d
- e22f21d486631d813c4ad77b1c106c621ec95bf002c19f4cb979312f198266f5
- e5a60c8f90e846fe22b3b0ec3675038d214cacd1564d6d2b1add9b9c54bc601b
- fe27abcbad72ede7fd668cfe2f9938d42248133b0aa068c9196a4766eaffc18e
- 104[.]237.233.38
- 106[.]187.38.21
- 144[.]76.109.88
- 148[.]251.204.131
- 78[.]129.139.134
- 78[.]129.139.147
- 88[.]99.17.148
- hxxp://104[.]237.233.38:9999
- hxxp://106[.]187.38.21/short_qr/work[.]php?c=
- hxxp://148[.]251.204.131:8060
- hxxp://78[.]129.139.134:9999
- hxxp://78[.]129.139.147:8060
- hxxp://arbiogaz[.]com/upload/work.php?c=
- hxxp://arch-tech[.]net/components/com_layer_slider/senditem.php?c=
- hxxp://azmwn.suliparwarda[.]com/wp-content/plugins/wpdatatables/panda.php?c=
- hxxp://azmwn.suliparwarda[.]com/wp-content/themes/twentyfifteen/logs.php?c=
- hxxp://bangortalk.org[.]uk/speakers.php?c=
- hxxp://best2.thebestconference[.]org/ccb/browse_cat.php?c=
- hxxp://bikekaidee[.]com/admin/404.php?c=
- hxxp://camco.com[.]pk/controls/data.aspx?c=
- hxxp://cgss.com[.]pk/data.aspx?c=
- hxxp://feribschat[.]eu/logs.php?c=
- hxxp://fifacare55[.]com/404.php?c=
- hxxp://ghanaconsulate.com[.]pk/data.aspx?c=
- hxxp://heartmade[.]ae/plugins/content/contact/senditem.php?c=
- hxxp://itcdubai[.]net/action/contact_gtc.php?c=
- hxxp://kale.alfa-bilisim[.]com/banka/3d/data.aspx?c=
- hxxp://kale.alfa-bilisim[.]com/content/data.aspx?c=
- hxxp://larsson-elevator[.]com/plugins/xmap/com_k2/com.php?c=
- hxxp://magical-energy[.]com/css.aspx?c=
- hxxp://magical-energy[.]com/css/css.aspx?c=
- hxxp://mainandstrand[.]com/work.php?c=
- hxxp://ohofifa[.]com/wp-content/themes/newspaper/mobile/includes/404.php?c=
- hxxp://ohofifa[.]com/wp-content/themes/newspaper/mobile/work.php?c=
- hxxp://projac.co[.]uk/senditem.php?c=
- hxxp://romix-group[.]com/modules/mod_wrapper/senditem.php?c=
- hxxps://78[.]129.139.134:6643
- hxxp://school.suliparwarda[.]com/components/com_akeeba/work.php?c=
- hxxp://school.suliparwarda[.]com/plugins/editors/codemirror/work.php?c=
- hxxps://coa.inducks[.]org/publication.php?c=
- hxxps://mhtevents[.]com/account.php?c=
- hxxps://skepticalscience[.]com/graphics.php?c=
- hxxp://suliparwarda[.]com/wp-content/plugins/entry-views/work.php?c=
- hxxp://suliparwarda[.]com/wp-content/themes/twentyfifteen/work.php?c=
- hxxps://wallpapercase[.]com/wp-content/themes/twentyfifteen/logs.php?c=
- hxxps://wallpapercase[.]com/wp-includes/customize/logs.php?c=
- hxxps://www.spearhead-training[.]com/action/point2.php?c=
- hxxps://www.spearhead-training[.]com//html/power.php?c=
- hxxps://www.spearhead-training[.]com/work.php?c=
- hxxp://taxconsultantsdubai[.]ae/wp-content/themes/config.php?c=
- hxxp://teeyaipakin[.]com/wp-content/plugins/all-in-one-seo-pack/404.php?c=
- hxxp://tmclub[.]eu/clubdata.php?c=
- hxxp://watyanagr.nfe.go[.]th/e-office/lib/work.php?c=
- hxxp://watyanagr.nfe.go[.]th/watyanagr/power.php?c=
- hxxp://whiver[.]in/power.php?c=
- hxxp://www.4seasonrentacar[.]com/viewsure/data.aspx?c=
- hxxp://www.akhtaredanesh[.]com/d/file/sym/work.php?c=
- hxxp://www.akhtaredanesh[.]com/d/oschool/power.php?c=
- hxxp://www.amarsarkar[.]com/webadmin/404.php?c=
- hxxp://www.amarsarkar[.]com/webadmin/inc/404.php?c=
- hxxp://www.arcadecreative[.]com/work.php?c=
- hxxp://www.armaholic[.]com/list.php?c=
- hxxp://www.asan-max[.]com/files/articles/css.aspx?c=
- hxxp://www.asan-max[.]com/files/articles/large/css.aspx?c=
- hxxp://www.autotrans[.]hr/index.php?c=
- hxxp://www.dafc.co[.]uk/news.php?c=
- hxxp://www.eapa[.]org/asphalt.php?c=
- hxxp://www.elev8tor[.]com/show-work.php?c=
- hxxp://www.jdarchs[.]com/work.php?c=
- hxxp://www.kunkrooann[.]com/inc/work.php?c=
- hxxp://www.mackellarscreenworks[.]com/work.php?c=
- hxxp://www.mitegen[.]com/mic_catalog.php?c=
- hxxp://www.nigelwhitfield[.]com/v2/work.php?c=
- hxxp://www.pomegranates[.]org/index.php?c=
- hxxp://www.ridefox[.]com/content.php?c=
- hxxp://www.shapingtomorrowsworld[.]org/category.php?c=
- hxxp://www.vanessajackson.co[.]uk/work.php?c=
- hxxp://www.wmg-global[.]com/wp-content/wp_fast_cache/wmg-global.com/senditem.php?c=
- hxxp://www.yaran[.]co//wp-content/plugins/so-masonry/logs.php?c=
- hxxp://www.yaran[.]co/wp-includes/widgets/logs.php?c=
- hxxp://www.ztm.waw[.]pl/pop.php?c=
Tip: 152 related IOCs (7 IP, 54 domain, 74 URL, 0 email, 17 file hash) to this threat have been found.
Overlaps
Source: Picussecurity - March 2022
Detection (six cases): 16bcb6cc38347a722bb7682799e9d9da40788e3ca15f29e46b475efe869d0a04, 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1, 40a6b4c6746e37d0c5ecb801e7656c9941f4839f94d8f4cd61eaf2b812feaabe, 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f, b2c10621c9c901f0f692cae0306baa840105231f35e6ec36e41b88eebd46df4c, de6ce9b75f4523a5b235f90fa00027be5920c97a972ad6cb2311953446c81e1d
Source: Trend Micro - June 2019
Detection (three cases): 104[.]237.233.38, 78[.]129.139.134, 88[.]99.17.148
Source: Kaspersky - April 2019
Detection (two cases): 104[.]237.233.38, 78[.]129.139.134
Source: Unit 42 - Palo Alto Networks - November 2017
Detection (100 cases): 106[.]187.38.21, 144[.]76.109.88, 148[.]251.204.131, hxxp://106[.]187.38.21/short_qr/work[.]php?c=, hxxp://arbiogaz[.]com/upload/work.php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/plugins/wpdatatables/panda.php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxp://bangortalk.org[.]uk/speakers.php?c=, hxxp://best2.thebestconference[.]org/ccb/browse_cat.php?c=, hxxp://camco.com[.]pk/controls/data.aspx?c=, hxxp://cgss.com[.]pk/data.aspx?c=, hxxp://feribschat[.]eu/logs.php?c=, hxxp://ghanaconsulate.com[.]pk/data.aspx?c=, hxxp://magical-energy[.]com/css.aspx?c=, hxxp://magical-energy[.]com/css/css.aspx?c=, hxxp://mainandstrand[.]com/work.php?c=, hxxp://school.suliparwarda[.]com/components/com_akeeba/work.php?c=, hxxp://school.suliparwarda[.]com/plugins/editors/codemirror/work.php?c=, hxxp://suliparwarda[.]com/wp-content/plugins/entry-views/work.php?c=, hxxp://suliparwarda[.]com/wp-content/themes/twentyfifteen/work.php?c=, hxxp://tmclub[.]eu/clubdata.php?c=, hxxp://watyanagr.nfe.go[.]th/e-office/lib/work.php?c=, hxxp://watyanagr.nfe.go[.]th/watyanagr/power.php?c=, hxxp://whiver[.]in/power.php?c=, hxxp://www.4seasonrentacar[.]com/viewsure/data.aspx?c=, hxxp://www.akhtaredanesh[.]com/d/file/sym/work.php?c=, hxxp://www.akhtaredanesh[.]com/d/oschool/power.php?c=, hxxp://www.arcadecreative[.]com/work.php?c=, hxxp://www.armaholic[.]com/list.php?c=, hxxp://www.asan-max[.]com/files/articles/css.aspx?c=, hxxp://www.asan-max[.]com/files/articles/large/css.aspx?c=, hxxp://www.autotrans[.]hr/index.php?c=, hxxp://www.dafc.co[.]uk/news.php?c=, hxxp://www.eapa[.]org/asphalt.php?c=, hxxp://www.elev8tor[.]com/show-work.php?c=, hxxp://www.jdarchs[.]com/work.php?c=, hxxp://www.kunkrooann[.]com/inc/work.php?c=, hxxp://www.mackellarscreenworks[.]com/work.php?c=, hxxp://www.mitegen[.]com/mic_catalog.php?c=, hxxp://www.nigelwhitfield[.]com/v2/work.php?c=, hxxp://www.pomegranates[.]org/index.php?c=, hxxp://www.ridefox[.]com/content.php?c=, hxxp://www.shapingtomorrowsworld[.]org/category.php?c=, hxxp://www.vanessajackson.co[.]uk/work.php?c=, hxxp://www.yaran[.]co//wp-content/plugins/so-masonry/logs.php?c=, hxxp://www.yaran[.]co/wp-includes/widgets/logs.php?c=, hxxp://www.ztm.waw[.]pl/pop.php?c=, hxxps://coa.inducks[.]org/publication.php?c=, hxxps://mhtevents[.]com/account.php?c=, hxxps://skepticalscience[.]com/graphics.php?c=, hxxps://wallpapercase[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxps://wallpapercase[.]com/wp-includes/customize/logs.php?c=, hxxps://www.spearhead-training[.]com//html/power.php?c=, hxxps://www.spearhead-training[.]com/work.php?c=, 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1, 40a6b4c6746e37d0c5ecb801e7656c9941f4839f94d8f4cd61eaf2b812feaabe, 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f, 917a6c816684f22934e2998f43633179e14dcc2e609c6931dd2fc36098c48028, a6673c6d52dd5361afd96f8143b88810812daa97004f69661da625aaaba9363b, de6ce9b75f4523a5b235f90fa00027be5920c97a972ad6cb2311953446c81e1d, arbiogaz[.]com, azmwn.suliparwarda[.]com, bangortalk.org[.]uk, best2.thebestconference[.]org, camco.com[.]pk, cgss.com[.]pk, coa.inducks[.]org, feribschat[.]eu, ghanaconsulate.com[.]pk, magical-energy[.]com, mainandstrand[.]com, mhtevents[.]com, school.suliparwarda[.]com, skepticalscience[.]com, suliparwarda[.]com, tmclub[.]eu, wallpapercase[.]com, watyanagr.nfe.go[.]th, whiver[.]in, www.4seasonrentacar[.]com, www.akhtaredanesh[.]com, www.arcadecreative[.]com, www.armaholic[.]com, www.asan-max[.]com, www.autotrans[.]hr, www.dafc.co[.]uk, www.eapa[.]org, www.elev8tor[.]com, www.jdarchs[.]com, www.kunkrooann[.]com, www.mackellarscreenworks[.]com, www.mitegen[.]com, www.nigelwhitfield[.]com, www.pomegranates[.]org, www.ridefox[.]com, www.shapingtomorrowsworld[.]org, www.spearhead-training[.]com, www.vanessajackson.co[.]uk, www.yaran[.]co, www.ztm.waw[.]pl
Source: Security 0wnage - November 2017
Detection (82 cases): 106[.]187.38.21, 148[.]251.204.131, hxxp://106[.]187.38.21/short_qr/work[.]php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/plugins/wpdatatables/panda.php?c=, hxxp://azmwn.suliparwarda[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxp://bangortalk.org[.]uk/speakers.php?c=, hxxp://best2.thebestconference[.]org/ccb/browse_cat.php?c=, hxxp://feribschat[.]eu/logs.php?c=, hxxp://magical-energy[.]com/css.aspx?c=, hxxp://magical-energy[.]com/css/css.aspx?c=, hxxp://mainandstrand[.]com/work.php?c=, hxxp://school.suliparwarda[.]com/components/com_akeeba/work.php?c=, hxxp://school.suliparwarda[.]com/plugins/editors/codemirror/work.php?c=, hxxp://suliparwarda[.]com/wp-content/plugins/entry-views/work.php?c=, hxxp://suliparwarda[.]com/wp-content/themes/twentyfifteen/work.php?c=, hxxp://tmclub[.]eu/clubdata.php?c=, hxxp://watyanagr.nfe.go[.]th/watyanagr/power.php?c=, hxxp://whiver[.]in/power.php?c=, hxxp://www.akhtaredanesh[.]com/d/file/sym/work.php?c=, hxxp://www.akhtaredanesh[.]com/d/oschool/power.php?c=, hxxp://www.arcadecreative[.]com/work.php?c=, hxxp://www.armaholic[.]com/list.php?c=, hxxp://www.asan-max[.]com/files/articles/css.aspx?c=, hxxp://www.asan-max[.]com/files/articles/large/css.aspx?c=, hxxp://www.autotrans[.]hr/index.php?c=, hxxp://www.dafc.co[.]uk/news.php?c=, hxxp://www.eapa[.]org/asphalt.php?c=, hxxp://www.elev8tor[.]com/show-work.php?c=, hxxp://www.jdarchs[.]com/work.php?c=, hxxp://www.kunkrooann[.]com/inc/work.php?c=, hxxp://www.mackellarscreenworks[.]com/work.php?c=, hxxp://www.mitegen[.]com/mic_catalog.php?c=, hxxp://www.nigelwhitfield[.]com/v2/work.php?c=, hxxp://www.pomegranates[.]org/index.php?c=, hxxp://www.ridefox[.]com/content.php?c=, hxxp://www.shapingtomorrowsworld[.]org/category.php?c=, hxxp://www.vanessajackson.co[.]uk/work.php?c=, hxxp://www.yaran[.]co//wp-content/plugins/so-masonry/logs.php?c=, hxxp://www.yaran[.]co/wp-includes/widgets/logs.php?c=, hxxp://www.ztm.waw[.]pl/pop.php?c=, hxxps://coa.inducks[.]org/publication.php?c=, hxxps://mhtevents[.]com/account.php?c=, hxxps://skepticalscience[.]com/graphics.php?c=, hxxps://wallpapercase[.]com/wp-content/themes/twentyfifteen/logs.php?c=, hxxps://wallpapercase[.]com/wp-includes/customize/logs.php?c=, hxxps://www.spearhead-training[.]com//html/power.php?c=, hxxps://www.spearhead-training[.]com/work.php?c=, azmwn.suliparwarda[.]com, bangortalk.org[.]uk, best2.thebestconference[.]org, coa.inducks[.]org, feribschat[.]eu, magical-energy[.]com, mainandstrand[.]com, mhtevents[.]com, school.suliparwarda[.]com, skepticalscience[.]com, suliparwarda[.]com, tmclub[.]eu, wallpapercase[.]com, watyanagr.nfe.go[.]th, whiver[.]in, www.akhtaredanesh[.]com, www.arcadecreative[.]com, www.armaholic[.]com, www.asan-max[.]com, www.autotrans[.]hr, www.dafc.co[.]uk, www.eapa[.]org, www.elev8tor[.]com, www.jdarchs[.]com, www.kunkrooann[.]com, www.mackellarscreenworks[.]com, www.mitegen[.]com, www.nigelwhitfield[.]com, www.pomegranates[.]org, www.ridefox[.]com, www.shapingtomorrowsworld[.]org, www.spearhead-training[.]com, www.vanessajackson.co[.]uk, www.yaran[.]co, www.ztm.waw[.]pl
Source: Security 0wnage - October 2017
Detection (five cases): 144[.]76.109.88, 148[.]251.204.131, 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1, 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f, 917a6c816684f22934e2998f43633179e14dcc2e609c6931dd2fc36098c48028
Source: Malwarebytes - September 2017
Detection (nine cases): 144[.]76.109.88, arch-tech[.]net, heartmade[.]ae, itcdubai[.]net, larsson-elevator[.]com, projac.co[.]uk, romix-group[.]com, taxconsultantsdubai[.]ae, wmg-global[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions About MuddyWater's 2017 Middle East Espionage Campaign
MuddyWater, an Iranian-linked APT group, conducted a sustained "living off the land" espionage campaign throughout 2017 targeting government agencies, telecom providers, and oil companies in Iraq, Saudi Arabia, and UAE. The group delivered its primary backdoor — POWERSTATS, a PowerShell-based implant — through malicious Office macro documents, and used a network of compromised legitimate websites as proxy relays to hide its real C2 server. ReaQta made the first public disclosure of MuddyWater in September 2017, and the group adapted rapidly to each publication, shifting infrastructure and expanding its toolset through November 2017.
The campaign is attributed to MuddyWater, a threat group assessed to operate on behalf of the Iranian government or to be an Iranian criminal organization engaged in espionage. ReaQta's analysis identified Iran as the likely originating country based on operator working hours consistent with Iranian time zones, the geographic focus on Iran's regional rivals, and the nature of the targeted sectors. MuddyWater is also tracked as TEMP.Zagros, Static Kitten, and Seedworm, and has since been formally attributed by the US Cyber Command and CISA to Iranian intelligence.
The primary goal was intelligence collection. MuddyWater operators showed strong interest in government agencies, telecommunications providers, and oil companies in Iraq, Saudi Arabia, and UAE — sectors of direct strategic value to Iran. The deeply compromised Iraqi telecom provider (10% of endpoints infected) and the high operator activity on Saudi and UAE victims compared to Pakistani victims despite lower infection counts indicates deliberate targeting of high-value intelligence sources rather than opportunistic spreading. ReaQta derived the espionage motivation from analysis of the backdoor's behaviors and the data it collected.
Despite Pakistan having the most raw infections, the real primary targets were Iraq, Saudi Arabia, and UAE. In Iraq, a major telecom provider had 10% of its endpoints compromised with POWERSTATS — an unusually deep penetration. Named victims include the Iraqi National Intelligence Service, Saudi Arabia's Ministry of Interior, Pakistan's Federal Investigation Agency, and the National Security Agency of an unnamed country. The broader victim set included governments, telecom companies, and oil infrastructure across the Middle East, with additional infections in Turkey, Jordan, Lebanon, Israel, Egypt, Tunisia, the UK, and the US — primarily travelers and diaspora from the primary target countries.
Iraq, Saudi Arabia, and UAE are all direct strategic rivals or regional competitors of Iran. Iraqi government and telecom infrastructure holds intelligence on Iranian border security, military movements, and diplomatic communications. Saudi Arabia is Iran's primary geopolitical adversary with control over significant oil production competing with Iran's. UAE serves as a major financial and logistics hub that Iran monitors for sanctions evasion and regional intelligence. The oil platform compromise also reflects interest in energy infrastructure that Iran monitors for pricing, production, and geopolitical leverage.
MuddyWater delivered POWERSTATS via spearphishing emails carrying Office documents with embedded VBA macros. When the victim opened the document and enabled macros, the macro executed PowerShell commands entirely in memory — no binary was written to disk, keeping the forensic footprint minimal. The PowerShell backdoor connected to one of many compromised legitimate websites acting as a proxy relay, which forwarded traffic to the real C2 server. This proxy layer made blocking and attribution significantly harder. Payload hosting evolved from GitHub to Pastebin to embedded macros across the campaign, and by November 2017 the group also deployed Koadic (a JScript RAT) and Meterpreter on selected high-value victims for additional post-exploitation capability.
MuddyWater's rapid adaptation to each public disclosure was notable. When ReaQta published the first report and GitHub blocked the payload repository, the group shifted to Pastebin within hours. When MalwareBytes published analysis referencing the Pastebin C2, the group changed its C2 IP the same day and moved to embedding payloads directly in documents. When Palo Alto and Saudi Arabia's NCSC published advisories, MuddyWater expanded its toolset with Koadic and Meterpreter within six days. The group cycled through four different C2 IPs in under two months. This speed of adaptation — all without missing significant operational tempo — reflects a well-resourced, actively managed operation rather than opportunistic malware distribution.
Block outbound connections to the 7 documented C2 IPs and monitor the 54 compromised proxy domains, but note that the proxy-relay C2 architecture makes IP and domain blocking insufficient on its own — behavioral detection is required. Disable VBA macros in Office documents from external sources and block macro-enabled Office attachments at the email gateway. Enable PowerShell Script Block Logging and AMSI to capture obfuscated POWERSTATS at runtime, since the malware leaves no binary on disk and cannot be detected through file scanning alone. Alert on PowerShell processes spawned by Office applications that make outbound HTTP connections or modify Registry Run keys. Monitor scheduled task creation by script processes and alert on any in-memory PowerShell sessions establishing external connections — the primary behavioral signature of POWERSTATS.