Threats Feed|MuddyWater|Last Updated 25/05/2026|AuthorCertfa Radar|Publish Date10/06/2019

MuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Brute-force,Backdoor,Malicious Macro,Malware,RAT,Trojan,Smishing,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

The MuddyWater threat actor group has resurfaced, launching sophisticated campaigns against targets in the Middle East, Asia and other parts of the world, using new tools like the multi-stage PowerShell backdoor POWERSTATS v3 and various post-exploitation tools. The campaigns involved spear-phishing emails sent from compromised accounts, leading to the deployment of malware designed for intelligence gathering. Targets included a university in Jordan and the Turkish government, highlighting the group's continued focus on geopolitical espionage. The report also discusses MuddyWater's connections to Android malware and the use of false flags to misattribute campaigns, showcasing the group's evolving tactics and infrastructure sophistication.

Detected Targets

TypeDescriptionConfidence
SectorDefense
Verified
SectorFinancial
Verified
SectorGovernment Agencies and Services
Verified
SectorEducation
Verified
SectorPolitical
Verified
SectorTelecommunication
Verified
RegionAfghanistan
Verified
RegionAzerbaijan
Verified
RegionBelarus
Verified
RegionDenmark
Verified
RegionEgypt
Verified
RegionGeorgia
Verified
RegionIndia
Verified
RegionIran
Verified
RegionIraq
Verified
RegionIsrael
Verified
RegionJordan
Verified
RegionJordan
Verified
RegionMalta
Verified
RegionNetherlands
Verified
RegionOman
Verified
RegionPakistan
Verified
RegionSaudi Arabia
Verified
RegionSwitzerland
Verified
RegionTajikistan
Verified
RegionTurkey
Verified
RegionTurkmenistan
Verified
RegionUnited Arab Emirates
Verified
RegionUnited States
Verified
RegionUzbekistan
Verified

Extracted IOCs

  • gladiyator[.]tk
  • valis-ti[.]cl
  • amazo0n.serveftp[.]com
  • ciscoupdate2019.gotdns[.]ch
  • getgooogle.hopto[.]org
  • googleads.hopto[.]org
  • shopcloths.ddns[.]net
  • www.latvia-usa[.]org
  • www.shareliverpoolfc.co[.]uk
  • zstoreshoping.ddns[.]net
  • 02f54da6c6f2f87ff7b713d46e058dedac1cedabd693643bb7f6dfe994b2105d
  • 04acd5721ad37ac5aa84e7f7e20986de0a532fb625a8bc75302a0f38c171cee3
  • 0ae4ce8c511a22da99c6edc4be86af1c5d3a7d2baf1e862925a503d8baae9fd7
  • 0e7e3c2c7fe34afc02c6e672ae00bc4e432b300ec184dec08440fba91b664999
  • 0faa2bb90de44ef87c7ee11165f7c702211dd603bdaea94af09cfecc3f525138
  • 11761d6cf365932540ccb95b6f20aa45379736cfde33742a004fc8ceccad7daf
  • 121adcf3a52cafd0204ca4d4a42a9a09d6c9f559bcb997e51dba79c6a5a04efd
  • 17405e9f8f889925521912aea72467330f3dffeaf8ec8678ef6f412204262896
  • 19e69e5925b9fac1a104fc37b06de42043276c17dac88be2f1d1815f7b56b3f6
  • 1dae45ea1f644c0a8e10c962d75fca1cedcfd39a88acef63869b7a5990c1c60b
  • 200c3d027b2d348b0633f8debbbab9f3efc465617727df9e3fdfa6ceac7d191b
  • 20bf83bf516b12d991d38fdc014add8ad5db03907a55303f02d913db261393a9
  • 24878dbde796c471a9d028f65421017afc087c958fb54c4b6c3cc7aeabbc1119
  • 264f2ea4a8fad97e66d5ad41a57517b4645fe4c4959d55370919379b844b0750
  • 26de4265303491bed1424d85b263481ac153c2b3513f9ee48ffb42c12312ac43
  • 276a765a10f98cda1a38d3a31e7483585ca3722ecad19d784441293acf1b7beb
  • 28a0131a9fda9fe2f2272c5091c77dc750da93d4a070dbd817af38723ea18f02
  • 2967f1acceaa7d121f8f2c46bc04a3c146c472997d43f11f98d967a88be6c095
  • 2ba871586176522fe75333e834c16025b01e1771e4c07bc13995adbfa77c45f5
  • 31cf13e8579f0589424631c6be659480f9a204a50a54073e7d7fe6c9c81fa0db
  • 336237b1ed2c99c0fef4c954490bd8282d6e46941d2ac2b6c9294a1aa9a254ed
  • 36be54812428b4967c3d25aafdc703567b42ad4536c089aefaef673ce36a958f
  • 36ccae4dffc70249c79cd3156de1cd238af8f7a3e47dc90a1c33476cf97a77b0
  • 3bfec096c4837d1e6485fe0ae0ea6f1c0b44edc611d4f2204cc9cf73c985cbc2
  • 3c0c58d4b9eefea56e2f7be3f07cdb73e659b4db688bfbf9eacd96ba5ab2dfe5
  • 3c75c2f7b299d9cc03a7ff91c568defaa39b4be02d58a75a85930ab23d2a2cff
  • 3deaa4072da43185d4213a38403383b7cefe92524b69ce4e7884a3ddc0903f6b
  • 3e6d39886d76ab3c08b26feae075e01e9fb3c90795fa52dd6c74e4ef8b590fe8
  • 3f06d2d2e1641952f44a2de4db037d3272cfa621fb9388cdb1074643f50c0705
  • 3fee29fefe4aa9386a11a7a615dd052ff89e21d87eee0fff5d6f933d9384ede2
  • 46f6eaa082f3def929dfabf2b7ce62abc47496f8543de932386bca6364023bad
  • 484f78eb4a3bb69d62491fdb84f2c81b7ae131ec8452a04d6018a634e961cd6a
  • 4ba618c04cbdc47de2ab5f2c91f466bc42163fd541de80ab8b5e50f687bbb91c
  • 4bd93e4a9826a65ade60117f6136cb4ed0e17beae8668a7c7981d15c0bed705a
  • 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1
  • 4e2cdfed691d6debab01c1733135b146817c94024177f9ef4b22726fac84322f
  • 503b2b01bb58fc433774e41a539ae9b06004c7557ac60e7d8a6823f5da428eb8
  • 5194f84cc52093bb4978167a9f2d5c0903e9de0b81ca20f492e4fc78b6a77655
  • 525ba2c8d35f6972ac8fcec8081ae35f6fe8119500be20a4113900fe57d6a0de
  • 57a9e2e6e715455827faefa982b4312b203189950fe285f1413174f5e812e408
  • 5d3d5fa9c6ffa64b2af0c5ce357cb6a16085280d32eb321d679b57472ffb1019
  • 5dbf6e347164d580665208b2bc04756857529121fd1c7861e84f18e8a6027924
  • 604e09e01e2bfbc8f3680abd8005906e3fbcd2f4edaf24d80cd7105ec6f991b1
  • 666625c87a29745b54710682823e3432fd7a54d2788cbcba2243406bc1b48ab3
  • 66733fe27591347f6b28bc7750ba1b47b2853f711adcdb1270951c6b92e795d6
  • 67c3c5af27d19f25bc55c8e36ef19b57c03b211ce0637055721ae4b0e57011a7
  • 6a441b2303aeb38309bf2cb70f1c97213b0fa2cf7a0f0f8251fe6dc9965ada3b
  • 6b4d271a48d118843aee3dee4481fa2930732ed7075db3241a8991418f00d92b
  • 6ccb3882c516fafc54444e09f5c60738831292be0231939bec9168a0203e01bb
  • 6ee79815f71e2eb4094455993472c7fb185cde484c8b5326e4754adcb1faf78e
  • 745b0e0793fc507d9e1ad7155beb7ac48f8a556e6ef06e43888cbefec3083f2f
  • 78da47f5a341909d1e6f50f8d39fdde8129ede86f04f3e88b2278e16c72e2461
  • 7e7b6923f3e2ee919d1ea1c8f8d9a915c52392bd6f9ab515e4eb95fa42355991
  • 818253f297fea7d8a2324ee1a233aabbaf3b0b4b9cdaa1ebd676fe00f2247388
  • 81c7787040ed5ecf21b6f80dc84bc147cec518986bf25aa933dd44c414b5f498
  • 8501c4df5995fd283e733ab00492f35aecb6ea2315b44e85abb90b3f067ccb64
  • 8674058edfbe636e550109fabb6403827c1bba4ab08833e9692099c96a43497a
  • 88e02850c575504bb4476f0d519cec8e6a562b72d17ed50b9d465d8e0de50093
  • 8ea17ed2cb662118937ed6fe189582cc11b2b73bb27a223d0468881ac5fcc08e
  • 9112505ff574b43dd27efc8afcf029841e1ea5193db90424b8b8b6b0e53c3437
  • 92bb4432cc9d2988ee4043e420a4df9c8caec4cd93ab258e07546781daa37086
  • 9389cf41e89a51860f918f29b55e34b5643264c990fe54273ffbbf5336a35a45
  • 9580aaca2e0cd607eaf54c3eb933e41538dc10cd341d41e3daa9185b2a6341c4
  • 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce
  • 98f0f2c42f703bfbb96de87367866c3cced76d5a8812c4cbc18a2be3da382c95
  • 999e4753749228a60d4d20cc5c5e27ca4275fe63e6083053a5b01b5225c8d53a
  • 9af8a93519d22ed04ffb9ccf6861c9df1b77dc5d22e0aeaff4a582dbf8660ba6
  • a35406d9ef82a68fbabb3c1e19911c9ed41bed335ef44a15037d1580c2b9dd12
  • a4f9509e865d0a387cb8f0367e35ffd259b193f5270aacb67cb99942071c60cc
  • a55aedff23bcdc83748d4e87ab992c0fb674a0af6b90687b2a2fc7cab52676a9
  • ae7350a2713d9a7f788c2c670fda44046183dfe646d9837ceaa0b6bad1d45a6e
  • b134bde3d8d141b9b4e824adaac87fc3eb40d3ab64682a73b2eb1743d7e3ceb0
  • b2242bc51ebe2c3abc5a8691546827070540db43843b8328bdb81f450cd1254b
  • b9d4752b892759bb0cb166ab565f050f4b6385dd67f4288ff2231c69ab984a26
  • be9fb556a3c7aef0329e768d7f903e7dd42a821abc663e11fb637ce33b007087
  • c175b2e9f0d73db293ca061ce95cdd92a423348aa162b14c158d97e9e7c3ff10
  • c19095433ac4884d3205a59e61c90752ecb4e4fa6a84e21f49ed82d9ec48aa3c
  • c2c2adecff2e517395571f4f9bee3b8cffed4521a8e1a3e3b363fd5e635f2eee
  • c63f1d364b9fa2c1023ce5a1b5fed12e1eba780c64276811c4b47743dfcbadbd
  • c84a61ba8c84ca1e879c4d8ac802ec260a8c426d89a09d8627a8c08ff6d88faf
  • cc685f30e2f6039d12b4cbc92e38f1d64ba75ac12cb86afce5261a11cf4931de
  • d320286e80d5785bbd14b10c00f5c9d38d9a781075d7d6ed4eb27c07d4788dbf
  • d5b7a5ae4156676b37543a3183df497367429ae2d01ef33ebc357c4bdd9864c3
  • d698c1d492332f312487e027d0665970b0462aceeeba3c91e762cff8579e7f72
  • d77d16c310cce09b872c91ca223b106f4b56572242ff5c4e756572070fac210f
  • dab2cd3ddfe29a89b3d80830c6a4950952a44b6c97a664f1e9c182318ae5f4da
  • de4a1622b498c1cc989be1a1480a23f4c4e9cd25e729a329cfadb7594c714358
  • de7b77f9c456d26e369263b6e1d001279b69e687b2d3029803ede21417d4f5fa
  • df1bd693c11893c5259c591dceef707aa0480ef5626529f8a5b0ef826e5c0dec
  • dff2e39b2e008ea89a3d6b36dcd9b8c927fb501d60c1ad5a52ed1ffe225da2e2
  • e241b152e3f672434636c527ae0ebbd08c777f488020c98efce8b324486335c5
  • e2f82b074074955eeca3b0dd7b2831192bee49de329d5d4b36742c9721c8ad94
  • e60c802b692a503f4f91e8809bb961b5423c602f6fb374de1af4d983415de3f1
  • e6812fa0e12cc1913bfc7eb6dceb638429048e3cc59ce576c012a1d27fa20959
  • e9617764411603ddd4e7f39603a4bdaf602e20126608b3717b1f6fcae60981f2
  • edde2eb39ed2f145c41e53e87d43add8de336d3e4d5c8d261f471d35edf3ed47
  • efdec1ad0830359632141186917fd32809360894e8c0a28c28d3d0a71f48ec2f
  • f1a69e2041ab8ab190d029d0e061f107ef1223b553e97c302e973a3b3c80f83e
  • f2b8d7ce968ed8d6c33116bcfb8aeed97d89ec1ebf4f505c891020dc79d0ddd3
  • f5ef4a45e19da1b94c684a6c6d51b86aec622562c45d67cb5aab554f21eb9061
  • f6707b5f41192353be3311fc7f48ee30465038366386b909e6cefaade70c91bc
  • fb773f7324fdca584fff7da490820c7243a10555c8ff717d21c039a5ba337a43
  • fbd63941a25253f5bafe69c9cc86c7effc6ff14b9adddd6f69e2f26ed39a77a4
  • ff349c8bf770ba09d3f9830e22ab6306c022f4bc1beb193b3b2cfe044f9d617b
  • ff9ef26fa3b0b76658a8c6696bf2f9d23f132d1d422050802749134c446f757e
  • 103[.]13.67.4
  • 104[.]237.233.17
  • 104[.]237.233.38
  • 104[.]237.233.40
  • 104[.]237.255.212
  • 134[.]19.215.3
  • 163[.]172.147.222
  • 185[.]117.75.116
  • 185[.]14.248.26
  • 185[.]162.235.182
  • 185[.]185.25.175
  • 185[.]244.149.218
  • 185[.]34.16.82
  • 192[.]168.1.104
  • 31[.]171.154.67
  • 38[.]132.99.167
  • 46[.]99.148.96
  • 51[.]77.97.65
  • 78[.]129.139.131
  • 78[.]129.139.134
  • 78[.]129.139.148
  • 79[.]106.224.203
  • 80[.]80.163.182
  • 80[.]90.87.201
  • 82[.]102.8.101
  • 88[.]99.17.148
  • 91[.]187.114.210
  • amazo0n.serveftp[.]com/data
  • hxxp://104[.]237.233.17
  • hxxp://134[.]19.215.3:443
  • hxxp://185[.]117.75.116/tmp[.]php
  • hxxp://185[.]14.248.26
  • hxxp://185[.]162.235.182
  • hxxp://185[.]185.25.175/ref45[.]php
  • hxxp://185[.]185.25.175/sdownloads/*.jpeg
  • hxxp://185[.]244.149.218/jpegdownload/*.jpeg
  • hxxp://185[.]34.16.82
  • hxxp://31[.]171.154.67
  • hxxp://38[.]132.99.167/crf[.]txt
  • hxxp://46[.]99.148.96
  • hxxp://51[.]77.97.65
  • hxxp://78[.]129.139.148
  • hxxp://79[.]106.224.203
  • hxxp://82[.]102.8.101/bcerrxy[.]php
  • hxxp://ciscoupdate2019.gotdns[.]ch/users.php
  • hxxp://gladiyator[.]tk
  • hxxp://googleads.hopto[.]org/data/ce28e899a8d3d00a.dat
  • hxxps://104[.]237.233.38:1022/aeacre65xe9sdvn3cjws9gbtnm84gl_ajl_ad2eoeohrmbpq5qc9j7gcsszq0jnbdnoulnmwgny3fv2kchrum0u5nmo5jv9ks4zs5-plkiys4me/
  • hxxps://104[.]237.233.38:8080/nud2wcl9wztiaomcufmboa18gwsmrc8k6vqgrxxfqvghyktellhts7_tg-d64spqdv4soj/
  • hxxps://104[.]237.233.38:8080/yizdgrm_4mrn_mb8pdhl_qfl2h49-aao0w-faxrxjadq9ph2jelimez10iwmk6pcnluziydtlv-/
  • hxxps://104[.]237.233.40:8443/zi5w0idm6alegcwdnumyywaha33bipzaylnupu-eccncmfnncxzv05fljob3wvwqh6uf01vi-1ykf96/
  • hxxps://104[.]237.255.212:443/gfabcrpi14rarcgvm-qt2g3sw3ztmql6iu0vg5oy21aok4gvmvyx_tcp_whhsnyqh7/
  • hxxps://78[.]129.139.134:8864/lzkp68tth_bpzghmmwxnpwy0vjimgwdrfk01pv2xu2fztbaevb-6rzbuprietwtbcuxru7ttsf3rzgfpbepd294bp2mgd/
  • hxxps://88[.]99.17.148:443/3g-g7dufhlwc8gpww3z9rgns1is8f83b-95phynvp-k9219kbhn-ichwxsfr35a117i2jz_ox9mupayrjw-3nhmbxuvdp4imokzt/
  • hxxp://valis-ti[.]cl/assets/main.php
  • hxxp://www.latvia-usa[.]org/wp-includes/customize/main.php
  • hxxp://www.shareliverpoolfc.co[.]uk/js/main.php
  • hxxp://zstoreshoping.ddns[.]net/users.php?tname=
  • zstoreshoping.ddns[.]net/data/
download

Tip: 174 related IOCs (27 IP, 10 domain, 32 URL, 0 email, 105 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics

Source: Picussecurity - March 2022

Detection (nine cases): 3deaa4072da43185d4213a38403383b7cefe92524b69ce4e7884a3ddc0903f6b, 484f78eb4a3bb69d62491fdb84f2c81b7ae131ec8452a04d6018a634e961cd6a, 4ba618c04cbdc47de2ab5f2c91f466bc42163fd541de80ab8b5e50f687bbb91c, 4bd93e4a9826a65ade60117f6136cb4ed0e17beae8668a7c7981d15c0bed705a, 503b2b01bb58fc433774e41a539ae9b06004c7557ac60e7d8a6823f5da428eb8, 6ee79815f71e2eb4094455993472c7fb185cde484c8b5326e4754adcb1faf78e, 81c7787040ed5ecf21b6f80dc84bc147cec518986bf25aa933dd44c414b5f498, 999e4753749228a60d4d20cc5c5e27ca4275fe63e6083053a5b01b5225c8d53a, e241b152e3f672434636c527ae0ebbd08c777f488020c98efce8b324486335c5

MuddyWaterMuddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike

Source: Prevailion - January 2020

Detection (four cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt, 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1, 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce

MuddyWaterMuddyWater’s Advanced Tactics Exploit CVE-2017-0199 in Global Campaigns

Source: ClearSky - June 2019

Detection (nine cases): 185[.]185.25.175, hxxp://185[.]185.25.175/ref45[.]php, 1dae45ea1f644c0a8e10c962d75fca1cedcfd39a88acef63869b7a5990c1c60b, 200c3d027b2d348b0633f8debbbab9f3efc465617727df9e3fdfa6ceac7d191b, 20bf83bf516b12d991d38fdc014add8ad5db03907a55303f02d913db261393a9, 98f0f2c42f703bfbb96de87367866c3cced76d5a8812c4cbc18a2be3da382c95, d5b7a5ae4156676b37543a3183df497367429ae2d01ef33ebc357c4bdd9864c3, d77d16c310cce09b872c91ca223b106f4b56572242ff5c4e756572070fac210f, f5ef4a45e19da1b94c684a6c6d51b86aec622562c45d67cb5aab554f21eb9061

MuddyWaterBlackWater Campaign: MuddyWater's Advanced Evasion and Persistence Techniques

Source: Rewterz - May 2019

Detection (four cases): 38[.]132.99.167, 82[.]102.8.101, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php

MuddyWaterMuddyWater's BlackWater: An In-depth Look at Advanced TTPs

Source: Cisco Talos - May 2019

Detection (four cases): 38[.]132.99.167, 82[.]102.8.101, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php

MuddyWaterDecoding MuddyWater: Inside the APT's Advanced Toolset and Deception Tactics

Source: Kaspersky - April 2019

Detection (three cases): 104[.]237.233.38, 104[.]237.233.40, 78[.]129.139.134

MuddyWaterAdvanced Spearphishing and PowerShell Backdoors: MuddyWater Targets Belarus, Turkey, and Ukraine

Source: Check Point - April 2019

Detection (one case): 185[.]117.75.116

SeedwormSeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants

Source: Rewterz - February 2019

Detection (four cases): 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 79[.]106.224.203

SeedwormSeedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors

Source: Symantec - December 2018

Detection (five cases): 185[.]34.16.82, 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 79[.]106.224.203

MuddyWaterMuddyWater Expands Spear-Phishing Operations across Multiple Countries and Sectors

Source: Securelist - October 2018

Detection (two cases): 104[.]237.233.40, 104[.]237.255.212

MuddyWaterMuddyWater APT Focuses on Espionage in the Middle East: A Technical Analysis

Source: Reaqta - November 2017

Detection (three cases): 104[.]237.233.38, 78[.]129.139.134, 88[.]99.17.148

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

MuddyWater Threat Campaign

Security researchers have uncovered new cyberattack campaigns associated with a threat group known as MuddyWater. During these campaigns, the attackers used sophisticated new tools, including backdoors and mobile malware disguised as normal apps, to infiltrate targets. Additionally, secret operational details belonging to the attackers were recently leaked on the messaging app Telegram, exposing their software code and a list of previously compromised victims.

The attacks are attributed to MuddyWater, a threat actor group historically known for targeting organizations in the Middle East and Asia. The group has been highly active over the last couple of years and is characterized by its ability to rapidly change its tactics and software when security researchers expose its activities. While they do not use highly advanced "zero-day" exploits, they are consistently successful because they continually evolve their deceptive methods.

The primary goal of the attack appears to be espionage and data theft. The attackers use fake emails to trick users into downloading malicious files, which then install secret "backdoor" programs on their computers. These backdoors allow the attackers to silently steal files, capture passwords, take screenshots, and map out the internal networks of the victims for further exploitation.

The scale of the targeting was broad and international. While the attackers have historically focused heavily on the Middle East and Asia, these recent campaigns show them expanding their reach to aim at new targets located in European countries and the United States.

Yes, the attackers primarily focused on government entities, including departments handling foreign affairs, defense, trade, and customs. They also heavily targeted the telecommunications sector, educational institutions, and finance organizations. Furthermore, certain mobile attacks appeared to target specific populations, such as users in Turkey and Afghanistan.

The attackers initially compromised legitimate email accounts and used them to send highly convincing "spear-phishing" emails to their targets. Once a victim opened a malicious document attached to the email, hidden scripts automatically downloaded and installed secondary backdoors onto the computer. From there, the attackers controlled the infected computers remotely to run commands and steal data.

Government agencies, telecommunications providers, and financial institutions hold vast amounts of sensitive national security, infrastructure, and citizen data. Gaining access to these entities allows threat actors to conduct large-scale surveillance, monitor communications, and steal strategic information that is highly valuable for geopolitical maneuvering or espionage.

Organizations should prioritize upgrading to smart email security solutions to catch malicious messages before they reach employees. Additionally, because these attacks rely heavily on tricking human users, it is critical to provide security awareness training so employees know how to spot and safely handle suspicious emails or mobile applications.

This is a highly targeted issue rather than a random, widespread virus. The attackers specifically select their victims, such as particular government offices or universities, and carefully craft deceptive emails designed to look like legitimate communications relevant to those specific individuals and organizations.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights