MuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Brute-force,Backdoor,Malicious Macro,Malware,RAT,Trojan,Smishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
The MuddyWater threat actor group has resurfaced, launching sophisticated campaigns against targets in the Middle East, Asia and other parts of the world, using new tools like the multi-stage PowerShell backdoor POWERSTATS v3 and various post-exploitation tools. The campaigns involved spear-phishing emails sent from compromised accounts, leading to the deployment of malware designed for intelligence gathering. Targets included a university in Jordan and the Turkish government, highlighting the group's continued focus on geopolitical espionage. The report also discusses MuddyWater's connections to Android malware and the use of false flags to misattribute campaigns, showcasing the group's evolving tactics and infrastructure sophistication.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense | Verified |
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Education | Verified |
| Sector | Political | Verified |
| Sector | Telecommunication | Verified |
| Region | Afghanistan | Verified |
| Region | Azerbaijan | Verified |
| Region | Belarus | Verified |
| Region | Denmark | Verified |
| Region | Egypt | Verified |
| Region | Georgia | Verified |
| Region | India | Verified |
| Region | Iran | Verified |
| Region | Iraq | Verified |
| Region | Israel | Verified |
| Region | Jordan | Verified |
| Region | Jordan | Verified |
| Region | Malta | Verified |
| Region | Netherlands | Verified |
| Region | Oman | Verified |
| Region | Pakistan | Verified |
| Region | Saudi Arabia | Verified |
| Region | Switzerland | Verified |
| Region | Tajikistan | Verified |
| Region | Turkey | Verified |
| Region | Turkmenistan | Verified |
| Region | United Arab Emirates | Verified |
| Region | United States | Verified |
| Region | Uzbekistan | Verified |
Extracted IOCs
- gladiyator[.]tk
- valis-ti[.]cl
- amazo0n.serveftp[.]com
- ciscoupdate2019.gotdns[.]ch
- getgooogle.hopto[.]org
- googleads.hopto[.]org
- shopcloths.ddns[.]net
- www.latvia-usa[.]org
- www.shareliverpoolfc.co[.]uk
- zstoreshoping.ddns[.]net
- 02f54da6c6f2f87ff7b713d46e058dedac1cedabd693643bb7f6dfe994b2105d
- 04acd5721ad37ac5aa84e7f7e20986de0a532fb625a8bc75302a0f38c171cee3
- 0ae4ce8c511a22da99c6edc4be86af1c5d3a7d2baf1e862925a503d8baae9fd7
- 0e7e3c2c7fe34afc02c6e672ae00bc4e432b300ec184dec08440fba91b664999
- 0faa2bb90de44ef87c7ee11165f7c702211dd603bdaea94af09cfecc3f525138
- 11761d6cf365932540ccb95b6f20aa45379736cfde33742a004fc8ceccad7daf
- 121adcf3a52cafd0204ca4d4a42a9a09d6c9f559bcb997e51dba79c6a5a04efd
- 17405e9f8f889925521912aea72467330f3dffeaf8ec8678ef6f412204262896
- 19e69e5925b9fac1a104fc37b06de42043276c17dac88be2f1d1815f7b56b3f6
- 1dae45ea1f644c0a8e10c962d75fca1cedcfd39a88acef63869b7a5990c1c60b
- 200c3d027b2d348b0633f8debbbab9f3efc465617727df9e3fdfa6ceac7d191b
- 20bf83bf516b12d991d38fdc014add8ad5db03907a55303f02d913db261393a9
- 24878dbde796c471a9d028f65421017afc087c958fb54c4b6c3cc7aeabbc1119
- 264f2ea4a8fad97e66d5ad41a57517b4645fe4c4959d55370919379b844b0750
- 26de4265303491bed1424d85b263481ac153c2b3513f9ee48ffb42c12312ac43
- 276a765a10f98cda1a38d3a31e7483585ca3722ecad19d784441293acf1b7beb
- 28a0131a9fda9fe2f2272c5091c77dc750da93d4a070dbd817af38723ea18f02
- 2967f1acceaa7d121f8f2c46bc04a3c146c472997d43f11f98d967a88be6c095
- 2ba871586176522fe75333e834c16025b01e1771e4c07bc13995adbfa77c45f5
- 31cf13e8579f0589424631c6be659480f9a204a50a54073e7d7fe6c9c81fa0db
- 336237b1ed2c99c0fef4c954490bd8282d6e46941d2ac2b6c9294a1aa9a254ed
- 36be54812428b4967c3d25aafdc703567b42ad4536c089aefaef673ce36a958f
- 36ccae4dffc70249c79cd3156de1cd238af8f7a3e47dc90a1c33476cf97a77b0
- 3bfec096c4837d1e6485fe0ae0ea6f1c0b44edc611d4f2204cc9cf73c985cbc2
- 3c0c58d4b9eefea56e2f7be3f07cdb73e659b4db688bfbf9eacd96ba5ab2dfe5
- 3c75c2f7b299d9cc03a7ff91c568defaa39b4be02d58a75a85930ab23d2a2cff
- 3deaa4072da43185d4213a38403383b7cefe92524b69ce4e7884a3ddc0903f6b
- 3e6d39886d76ab3c08b26feae075e01e9fb3c90795fa52dd6c74e4ef8b590fe8
- 3f06d2d2e1641952f44a2de4db037d3272cfa621fb9388cdb1074643f50c0705
- 3fee29fefe4aa9386a11a7a615dd052ff89e21d87eee0fff5d6f933d9384ede2
- 46f6eaa082f3def929dfabf2b7ce62abc47496f8543de932386bca6364023bad
- 484f78eb4a3bb69d62491fdb84f2c81b7ae131ec8452a04d6018a634e961cd6a
- 4ba618c04cbdc47de2ab5f2c91f466bc42163fd541de80ab8b5e50f687bbb91c
- 4bd93e4a9826a65ade60117f6136cb4ed0e17beae8668a7c7981d15c0bed705a
- 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1
- 4e2cdfed691d6debab01c1733135b146817c94024177f9ef4b22726fac84322f
- 503b2b01bb58fc433774e41a539ae9b06004c7557ac60e7d8a6823f5da428eb8
- 5194f84cc52093bb4978167a9f2d5c0903e9de0b81ca20f492e4fc78b6a77655
- 525ba2c8d35f6972ac8fcec8081ae35f6fe8119500be20a4113900fe57d6a0de
- 57a9e2e6e715455827faefa982b4312b203189950fe285f1413174f5e812e408
- 5d3d5fa9c6ffa64b2af0c5ce357cb6a16085280d32eb321d679b57472ffb1019
- 5dbf6e347164d580665208b2bc04756857529121fd1c7861e84f18e8a6027924
- 604e09e01e2bfbc8f3680abd8005906e3fbcd2f4edaf24d80cd7105ec6f991b1
- 666625c87a29745b54710682823e3432fd7a54d2788cbcba2243406bc1b48ab3
- 66733fe27591347f6b28bc7750ba1b47b2853f711adcdb1270951c6b92e795d6
- 67c3c5af27d19f25bc55c8e36ef19b57c03b211ce0637055721ae4b0e57011a7
- 6a441b2303aeb38309bf2cb70f1c97213b0fa2cf7a0f0f8251fe6dc9965ada3b
- 6b4d271a48d118843aee3dee4481fa2930732ed7075db3241a8991418f00d92b
- 6ccb3882c516fafc54444e09f5c60738831292be0231939bec9168a0203e01bb
- 6ee79815f71e2eb4094455993472c7fb185cde484c8b5326e4754adcb1faf78e
- 745b0e0793fc507d9e1ad7155beb7ac48f8a556e6ef06e43888cbefec3083f2f
- 78da47f5a341909d1e6f50f8d39fdde8129ede86f04f3e88b2278e16c72e2461
- 7e7b6923f3e2ee919d1ea1c8f8d9a915c52392bd6f9ab515e4eb95fa42355991
- 818253f297fea7d8a2324ee1a233aabbaf3b0b4b9cdaa1ebd676fe00f2247388
- 81c7787040ed5ecf21b6f80dc84bc147cec518986bf25aa933dd44c414b5f498
- 8501c4df5995fd283e733ab00492f35aecb6ea2315b44e85abb90b3f067ccb64
- 8674058edfbe636e550109fabb6403827c1bba4ab08833e9692099c96a43497a
- 88e02850c575504bb4476f0d519cec8e6a562b72d17ed50b9d465d8e0de50093
- 8ea17ed2cb662118937ed6fe189582cc11b2b73bb27a223d0468881ac5fcc08e
- 9112505ff574b43dd27efc8afcf029841e1ea5193db90424b8b8b6b0e53c3437
- 92bb4432cc9d2988ee4043e420a4df9c8caec4cd93ab258e07546781daa37086
- 9389cf41e89a51860f918f29b55e34b5643264c990fe54273ffbbf5336a35a45
- 9580aaca2e0cd607eaf54c3eb933e41538dc10cd341d41e3daa9185b2a6341c4
- 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce
- 98f0f2c42f703bfbb96de87367866c3cced76d5a8812c4cbc18a2be3da382c95
- 999e4753749228a60d4d20cc5c5e27ca4275fe63e6083053a5b01b5225c8d53a
- 9af8a93519d22ed04ffb9ccf6861c9df1b77dc5d22e0aeaff4a582dbf8660ba6
- a35406d9ef82a68fbabb3c1e19911c9ed41bed335ef44a15037d1580c2b9dd12
- a4f9509e865d0a387cb8f0367e35ffd259b193f5270aacb67cb99942071c60cc
- a55aedff23bcdc83748d4e87ab992c0fb674a0af6b90687b2a2fc7cab52676a9
- ae7350a2713d9a7f788c2c670fda44046183dfe646d9837ceaa0b6bad1d45a6e
- b134bde3d8d141b9b4e824adaac87fc3eb40d3ab64682a73b2eb1743d7e3ceb0
- b2242bc51ebe2c3abc5a8691546827070540db43843b8328bdb81f450cd1254b
- b9d4752b892759bb0cb166ab565f050f4b6385dd67f4288ff2231c69ab984a26
- be9fb556a3c7aef0329e768d7f903e7dd42a821abc663e11fb637ce33b007087
- c175b2e9f0d73db293ca061ce95cdd92a423348aa162b14c158d97e9e7c3ff10
- c19095433ac4884d3205a59e61c90752ecb4e4fa6a84e21f49ed82d9ec48aa3c
- c2c2adecff2e517395571f4f9bee3b8cffed4521a8e1a3e3b363fd5e635f2eee
- c63f1d364b9fa2c1023ce5a1b5fed12e1eba780c64276811c4b47743dfcbadbd
- c84a61ba8c84ca1e879c4d8ac802ec260a8c426d89a09d8627a8c08ff6d88faf
- cc685f30e2f6039d12b4cbc92e38f1d64ba75ac12cb86afce5261a11cf4931de
- d320286e80d5785bbd14b10c00f5c9d38d9a781075d7d6ed4eb27c07d4788dbf
- d5b7a5ae4156676b37543a3183df497367429ae2d01ef33ebc357c4bdd9864c3
- d698c1d492332f312487e027d0665970b0462aceeeba3c91e762cff8579e7f72
- d77d16c310cce09b872c91ca223b106f4b56572242ff5c4e756572070fac210f
- dab2cd3ddfe29a89b3d80830c6a4950952a44b6c97a664f1e9c182318ae5f4da
- de4a1622b498c1cc989be1a1480a23f4c4e9cd25e729a329cfadb7594c714358
- de7b77f9c456d26e369263b6e1d001279b69e687b2d3029803ede21417d4f5fa
- df1bd693c11893c5259c591dceef707aa0480ef5626529f8a5b0ef826e5c0dec
- dff2e39b2e008ea89a3d6b36dcd9b8c927fb501d60c1ad5a52ed1ffe225da2e2
- e241b152e3f672434636c527ae0ebbd08c777f488020c98efce8b324486335c5
- e2f82b074074955eeca3b0dd7b2831192bee49de329d5d4b36742c9721c8ad94
- e60c802b692a503f4f91e8809bb961b5423c602f6fb374de1af4d983415de3f1
- e6812fa0e12cc1913bfc7eb6dceb638429048e3cc59ce576c012a1d27fa20959
- e9617764411603ddd4e7f39603a4bdaf602e20126608b3717b1f6fcae60981f2
- edde2eb39ed2f145c41e53e87d43add8de336d3e4d5c8d261f471d35edf3ed47
- efdec1ad0830359632141186917fd32809360894e8c0a28c28d3d0a71f48ec2f
- f1a69e2041ab8ab190d029d0e061f107ef1223b553e97c302e973a3b3c80f83e
- f2b8d7ce968ed8d6c33116bcfb8aeed97d89ec1ebf4f505c891020dc79d0ddd3
- f5ef4a45e19da1b94c684a6c6d51b86aec622562c45d67cb5aab554f21eb9061
- f6707b5f41192353be3311fc7f48ee30465038366386b909e6cefaade70c91bc
- fb773f7324fdca584fff7da490820c7243a10555c8ff717d21c039a5ba337a43
- fbd63941a25253f5bafe69c9cc86c7effc6ff14b9adddd6f69e2f26ed39a77a4
- ff349c8bf770ba09d3f9830e22ab6306c022f4bc1beb193b3b2cfe044f9d617b
- ff9ef26fa3b0b76658a8c6696bf2f9d23f132d1d422050802749134c446f757e
- 103[.]13.67.4
- 104[.]237.233.17
- 104[.]237.233.38
- 104[.]237.233.40
- 104[.]237.255.212
- 134[.]19.215.3
- 163[.]172.147.222
- 185[.]117.75.116
- 185[.]14.248.26
- 185[.]162.235.182
- 185[.]185.25.175
- 185[.]244.149.218
- 185[.]34.16.82
- 192[.]168.1.104
- 31[.]171.154.67
- 38[.]132.99.167
- 46[.]99.148.96
- 51[.]77.97.65
- 78[.]129.139.131
- 78[.]129.139.134
- 78[.]129.139.148
- 79[.]106.224.203
- 80[.]80.163.182
- 80[.]90.87.201
- 82[.]102.8.101
- 88[.]99.17.148
- 91[.]187.114.210
- amazo0n.serveftp[.]com/data
- hxxp://104[.]237.233.17
- hxxp://134[.]19.215.3:443
- hxxp://185[.]117.75.116/tmp[.]php
- hxxp://185[.]14.248.26
- hxxp://185[.]162.235.182
- hxxp://185[.]185.25.175/ref45[.]php
- hxxp://185[.]185.25.175/sdownloads/*.jpeg
- hxxp://185[.]244.149.218/jpegdownload/*.jpeg
- hxxp://185[.]34.16.82
- hxxp://31[.]171.154.67
- hxxp://38[.]132.99.167/crf[.]txt
- hxxp://46[.]99.148.96
- hxxp://51[.]77.97.65
- hxxp://78[.]129.139.148
- hxxp://79[.]106.224.203
- hxxp://82[.]102.8.101/bcerrxy[.]php
- hxxp://ciscoupdate2019.gotdns[.]ch/users.php
- hxxp://gladiyator[.]tk
- hxxp://googleads.hopto[.]org/data/ce28e899a8d3d00a.dat
- hxxps://104[.]237.233.38:1022/aeacre65xe9sdvn3cjws9gbtnm84gl_ajl_ad2eoeohrmbpq5qc9j7gcsszq0jnbdnoulnmwgny3fv2kchrum0u5nmo5jv9ks4zs5-plkiys4me/
- hxxps://104[.]237.233.38:8080/nud2wcl9wztiaomcufmboa18gwsmrc8k6vqgrxxfqvghyktellhts7_tg-d64spqdv4soj/
- hxxps://104[.]237.233.38:8080/yizdgrm_4mrn_mb8pdhl_qfl2h49-aao0w-faxrxjadq9ph2jelimez10iwmk6pcnluziydtlv-/
- hxxps://104[.]237.233.40:8443/zi5w0idm6alegcwdnumyywaha33bipzaylnupu-eccncmfnncxzv05fljob3wvwqh6uf01vi-1ykf96/
- hxxps://104[.]237.255.212:443/gfabcrpi14rarcgvm-qt2g3sw3ztmql6iu0vg5oy21aok4gvmvyx_tcp_whhsnyqh7/
- hxxps://78[.]129.139.134:8864/lzkp68tth_bpzghmmwxnpwy0vjimgwdrfk01pv2xu2fztbaevb-6rzbuprietwtbcuxru7ttsf3rzgfpbepd294bp2mgd/
- hxxps://88[.]99.17.148:443/3g-g7dufhlwc8gpww3z9rgns1is8f83b-95phynvp-k9219kbhn-ichwxsfr35a117i2jz_ox9mupayrjw-3nhmbxuvdp4imokzt/
- hxxp://valis-ti[.]cl/assets/main.php
- hxxp://www.latvia-usa[.]org/wp-includes/customize/main.php
- hxxp://www.shareliverpoolfc.co[.]uk/js/main.php
- hxxp://zstoreshoping.ddns[.]net/users.php?tname=
- zstoreshoping.ddns[.]net/data/
Tip: 174 related IOCs (27 IP, 10 domain, 32 URL, 0 email, 105 file hash) to this threat have been found.
Overlaps
Source: Picussecurity - March 2022
Detection (nine cases): 3deaa4072da43185d4213a38403383b7cefe92524b69ce4e7884a3ddc0903f6b, 484f78eb4a3bb69d62491fdb84f2c81b7ae131ec8452a04d6018a634e961cd6a, 4ba618c04cbdc47de2ab5f2c91f466bc42163fd541de80ab8b5e50f687bbb91c, 4bd93e4a9826a65ade60117f6136cb4ed0e17beae8668a7c7981d15c0bed705a, 503b2b01bb58fc433774e41a539ae9b06004c7557ac60e7d8a6823f5da428eb8, 6ee79815f71e2eb4094455993472c7fb185cde484c8b5326e4754adcb1faf78e, 81c7787040ed5ecf21b6f80dc84bc147cec518986bf25aa933dd44c414b5f498, 999e4753749228a60d4d20cc5c5e27ca4275fe63e6083053a5b01b5225c8d53a, e241b152e3f672434636c527ae0ebbd08c777f488020c98efce8b324486335c5
Source: Prevailion - January 2020
Detection (four cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt, 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1, 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce
Source: ClearSky - June 2019
Detection (nine cases): 185[.]185.25.175, hxxp://185[.]185.25.175/ref45[.]php, 1dae45ea1f644c0a8e10c962d75fca1cedcfd39a88acef63869b7a5990c1c60b, 200c3d027b2d348b0633f8debbbab9f3efc465617727df9e3fdfa6ceac7d191b, 20bf83bf516b12d991d38fdc014add8ad5db03907a55303f02d913db261393a9, 98f0f2c42f703bfbb96de87367866c3cced76d5a8812c4cbc18a2be3da382c95, d5b7a5ae4156676b37543a3183df497367429ae2d01ef33ebc357c4bdd9864c3, d77d16c310cce09b872c91ca223b106f4b56572242ff5c4e756572070fac210f, f5ef4a45e19da1b94c684a6c6d51b86aec622562c45d67cb5aab554f21eb9061
Source: Rewterz - May 2019
Detection (four cases): 38[.]132.99.167, 82[.]102.8.101, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php
Source: Cisco Talos - May 2019
Detection (four cases): 38[.]132.99.167, 82[.]102.8.101, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php
Source: Kaspersky - April 2019
Detection (three cases): 104[.]237.233.38, 104[.]237.233.40, 78[.]129.139.134
Source: Check Point - April 2019
Detection (one case): 185[.]117.75.116
Source: Rewterz - February 2019
Detection (four cases): 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 79[.]106.224.203
Source: Symantec - December 2018
Detection (five cases): 185[.]34.16.82, 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 79[.]106.224.203
Source: Securelist - October 2018
Detection (two cases): 104[.]237.233.40, 104[.]237.255.212
Source: Reaqta - November 2017
Detection (three cases): 104[.]237.233.38, 78[.]129.139.134, 88[.]99.17.148
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
MuddyWater Threat Campaign
Security researchers have uncovered new cyberattack campaigns associated with a threat group known as MuddyWater. During these campaigns, the attackers used sophisticated new tools, including backdoors and mobile malware disguised as normal apps, to infiltrate targets. Additionally, secret operational details belonging to the attackers were recently leaked on the messaging app Telegram, exposing their software code and a list of previously compromised victims.
The attacks are attributed to MuddyWater, a threat actor group historically known for targeting organizations in the Middle East and Asia. The group has been highly active over the last couple of years and is characterized by its ability to rapidly change its tactics and software when security researchers expose its activities. While they do not use highly advanced "zero-day" exploits, they are consistently successful because they continually evolve their deceptive methods.
The primary goal of the attack appears to be espionage and data theft. The attackers use fake emails to trick users into downloading malicious files, which then install secret "backdoor" programs on their computers. These backdoors allow the attackers to silently steal files, capture passwords, take screenshots, and map out the internal networks of the victims for further exploitation.
The scale of the targeting was broad and international. While the attackers have historically focused heavily on the Middle East and Asia, these recent campaigns show them expanding their reach to aim at new targets located in European countries and the United States.
Yes, the attackers primarily focused on government entities, including departments handling foreign affairs, defense, trade, and customs. They also heavily targeted the telecommunications sector, educational institutions, and finance organizations. Furthermore, certain mobile attacks appeared to target specific populations, such as users in Turkey and Afghanistan.
The attackers initially compromised legitimate email accounts and used them to send highly convincing "spear-phishing" emails to their targets. Once a victim opened a malicious document attached to the email, hidden scripts automatically downloaded and installed secondary backdoors onto the computer. From there, the attackers controlled the infected computers remotely to run commands and steal data.
Government agencies, telecommunications providers, and financial institutions hold vast amounts of sensitive national security, infrastructure, and citizen data. Gaining access to these entities allows threat actors to conduct large-scale surveillance, monitor communications, and steal strategic information that is highly valuable for geopolitical maneuvering or espionage.
Organizations should prioritize upgrading to smart email security solutions to catch malicious messages before they reach employees. Additionally, because these attacks rely heavily on tricking human users, it is critical to provide security awareness training so employees know how to spot and safely handle suspicious emails or mobile applications.
This is a highly targeted issue rather than a random, widespread virus. The attackers specifically select their victims, such as particular government offices or universities, and carefully craft deceptive emails designed to look like legitimate communications relevant to those specific individuals and organizations.