Threats Feed|MuddyWater|Last Updated 27/08/2026|AuthorCertfa Radar|Publish Date15/10/2018

MuddyWater APT's Spear Phishing Campaigns Target Middle East's Sectors

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Dropper,Malicious Macro,Malware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The MuddyWater APT group has been leveraging spear phishing attacks with malicious Word documents to infiltrate systems in the oil, military, telecom, and government sectors. These documents, often in the native language of the target, entice users to enable macros, leading to a chain of malicious activities. The malware, once activated, employs techniques like modifying registry keys, creating scheduled tasks, and using PowerShell to decode payloads and establish persistence. It cleverly evades detection by disguising its activities under seemingly legitimate processes and alters security settings like disabling firewalls and antivirus. Network analysis revealed beaconing to C2 servers, indicating a sophisticated level of stealth and persistence.

Detected Targets

TypeDescriptionConfidence
SectorGovernment Agencies and Services
Medium
RegionJordan
Verified
RegionPakistan
High
RegionTurkey
High

Extracted IOCs

  • addorg[.]org
  • alaqaba[.]com
  • ambiances-toiles[.]fr
  • apidubai[.]ae
  • botanikbahcesi[.]com
  • britishofficefitout[.]com
  • buy4you[.]pk
  • canbeginsaat[.]com
  • dailysportsgossips[.]com
  • gcmbdin.edu[.]pk
  • goolineb2b[.]com
  • hmholdings360.co[.]za
  • mediaology.com[.]pk
  • mumtazandbrohi[.]com
  • mycogentrading[.]com
  • nakoserum[.]com
  • pmdpk[.]com
  • themotoringcalendar.co[.]za
  • triconfabrication[.]com
  • wegallop[.]com
  • 16ac1a2c1e1c3b49e1a3a48fb71cc74f
  • bfb4fc96c1ba657107c7c60845f6ab720634c8a9214943b5221378a37a8916cd
  • 104[.]18.54.26
  • 173[.]212.229.48
  • 185[.]56.88.14
  • 185[.]82.222.239
  • 192[.]169.82.62
  • 192[.]185.166.22
  • 192[.]185.166.225
  • 192[.]185.166.227
  • 192[.]185.24.71
  • 192[.]185.75.15
  • 195[.]229.192.139
  • 196[.]40.100.202
  • 196[.]40.100.204
  • 196[.]41.137.185
  • 209[.]99.40.223
  • 217[.]160.0.2
  • 45[.]33.114.180
  • 5[.]250.241.18
  • 54[.]243.123.39
  • 86[.]107.58.132
  • 86[.]96.202.165
  • 89[.]107.58.132
  • 94[.]130.116.248
download

Tip: 45 related IOCs (23 IP, 20 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater Expands Spear-Phishing Operations across Multiple Countries and Sectors

Source: Securelist - October 2018

Detection (one case): 16ac1a2c1e1c3b49e1a3a48fb71cc74f

MuddyWaterCyber Espionage Evolution: MuddyWater’s Obfuscation Techniques and Anti-Analysis Measures

Source: Security 0wnage - May 2018

Detection (three cases): ambiances-toiles[.]fr, hmholdings360.co[.]za, themotoringcalendar.co[.]za

TEMP.ZagrosMulti-Stage Spear Phishing Attack Traced to Iran: TEMP.Zagros in Action

Source: Mandiant - March 2018

Detection (four cases): alaqaba[.]com, ambiances-toiles[.]fr, hmholdings360.co[.]za, themotoringcalendar.co[.]za

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

MuddyWater Cyber Campaign

A cyber attack campaign targeted specific organizations by sending email attachments disguised as important documents. When recipients opened the files and enabled interactive content, hidden background commands infected the computer, disabled security defenses, and allowed remote control by external attackers.

The operation was conducted by an advanced threat actor group known as MuddyWater. This group is recognized for orchestrating cyber operations against high-value government, critical infrastructure, and commercial targets primarily located throughout the Middle East.

The primary goal was to breach organizational networks, disable local antivirus defenses, and establish persistent, covert remote access for monitoring or data collection. The campaign specifically focused on high-value sectors including government, military, oil, and telecommunications organizations in countries such as Saudi Arabia, the UAE, Jordan, and Iraq.

This activity represents a highly targeted cyber attack rather than a broad, random malware outbreak. The attackers specifically customized their malicious documents with local languages and relevant file titles tailored directly to their intended target individuals and entities.

Attackers sent tailored phishing emails containing Word documents with blurry preview images. Once the victim enabled document macros, the malware used legitimate built-in Windows administrative utilities to install hidden files, schedule automatic startups, shut off local security tools, and communicate back to servers disguised as ordinary website traffic.

Entities operating in critical infrastructure, defense, government, and telecommunications manage vital economic, military, and communications data. Gaining access to these systems provides attackers with valuable strategic intelligence and long-term visibility into core operational networks.

Individuals should never enable macros or click "Enable Content" on unexpected document attachments, particularly those displaying blurred text. Organizations should deploy behavioral endpoint monitoring tools to flag unauthorized system modifications and set up real-time alerting for suspicious network communications.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights