Threats Feed|MuddyWater|Last Updated 29/07/2026|AuthorCertfa Radar|Publish Date20/05/2019

MuddyWater's BlackWater: An In-depth Look at Advanced TTPs

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Malicious Macro,Trojan,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The MuddyWater-associated BlackWater campaign has displayed advanced TTPs in its latest activities. Using obfuscated VBA and PowerShell scripts, the threat actors establish persistence via registry keys and utilize multi-staging payloads. The campaign employs an open-source framework, FruityC2, to further enumerate the victim's host machine and evade signature-based detection mechanisms. The actor-controlled servers are used for command and control, making host-based detection challenging. Compared to earlier samples, the new tactics require a multi-step investigative approach.

Detected Targets

TypeDescriptionConfidence
RegionMiddle East Countries
Medium

Extracted IOCs

  • 062a8728e7fcf2ff453efc56da60631c738d9cd6853d8701818f18a4e77f8717
  • 0d3e0c26f7f53dff444a37758b414720286f92da55e33ca0e69edc3c7f040ce2
  • 0f3cabc7f1e69d4a09856cc0135f7945850c1eb6aeecd010f788b3b8b4d91cad
  • 4dd641df0f47cb7655032113343d53c0e7180d42e3549d08eb7cb83296b22f60
  • 576d1d98d8669df624219d28abcbb2be0080272fa57bf7a637e2a9a669e37acf
  • 6f882cc0cddd03bc123c8544c4b1c8b9267f4143936964a128aa63762e582aad
  • 9d998502c3999c4715c880882efa409c39dd6f7e4d8725c2763a30fbb55414b7
  • a3bb6b3872dd7f0812231a480881d4d818d2dea7d2c8baed858b20cb318da981
  • b2600ac9b83e5bb5f3d128dbb337ab1efcdc6ce404adb6678b062e95dbf10c93
  • bef9051bb6e85d94c4cfc4e03359b31584be027e87758483e3b1e65d389483e6
  • 136[.]243.87.112
  • 38[.]132.99.167
  • 82[.]102.8.101
  • 94[.]23.148.194
  • hxxp://136[.]243.87.112:3000/kls6yug5df
  • hxxp://136[.]243.87.112:3000/ll5jh6f4bh
  • hxxp://136[.]243.87.112:3000/y3zp6ns7kg
  • hxxp://38[.]132.99.167/crf[.]txt
  • hxxp://82[.]102.8.101:80/bcerrxy[.]php?rcecms=blackwater
  • hxxp://82[.]102.8.101/bcerrxy[.]php
  • hxxp://94[.]23.148.194/serverscript/clientfrontline/
  • hxxp://94[.]23.148.194/serverscript/clientfrontline/getcommand[.]php
  • hxxp://94[.]23.148.194/serverscript/clientfrontline/helloserver[.]php
download

Tip: 23 related IOCs (4 IP, 0 domain, 9 URL, 0 email, 10 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics

Source: Picussecurity - March 2022

Detection (three cases): 0d3e0c26f7f53dff444a37758b414720286f92da55e33ca0e69edc3c7f040ce2, a3bb6b3872dd7f0812231a480881d4d818d2dea7d2c8baed858b20cb318da981, bef9051bb6e85d94c4cfc4e03359b31584be027e87758483e3b1e65d389483e6

MuddyWaterMuddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike

Source: Prevailion - January 2020

Detection (two cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt

MuddyWaterMuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

Source: Trend Micro - June 2019

Detection (four cases): 38[.]132.99.167, 82[.]102.8.101, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php

MuddyWaterBlackWater Campaign: MuddyWater's Advanced Evasion and Persistence Techniques

Source: Rewterz - May 2019

Detection (13 cases): 136[.]243.87.112, 38[.]132.99.167, 82[.]102.8.101, 94[.]23.148.194, hxxp://136[.]243.87.112:3000/kls6yug5df, hxxp://136[.]243.87.112:3000/ll5jh6f4bh, hxxp://136[.]243.87.112:3000/y3zp6ns7kg, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php, hxxp://82[.]102.8.101:80/bcerrxy[.]php?rcecms=blackwater, hxxp://94[.]23.148.194/serverscript/clientfrontline/, hxxp://94[.]23.148.194/serverscript/clientfrontline/getcommand[.]php, hxxp://94[.]23.148.194/serverscript/clientfrontline/helloserver[.]php

MuddyWaterMuddyWater APT Targets Kurdish Political Groups and Turkish Defense Sector

Source: ClearSky - April 2019

Detection (six cases): 94[.]23.148.194, 062a8728e7fcf2ff453efc56da60631c738d9cd6853d8701818f18a4e77f8717, 0d3e0c26f7f53dff444a37758b414720286f92da55e33ca0e69edc3c7f040ce2, 4dd641df0f47cb7655032113343d53c0e7180d42e3549d08eb7cb83296b22f60, 6f882cc0cddd03bc123c8544c4b1c8b9267f4143936964a128aa63762e582aad, bef9051bb6e85d94c4cfc4e03359b31584be027e87758483e3b1e65d389483e6

MuddyWaterMuddyWater Cyber Campaign Expands to Target Korek Telecom in Iraq

Source: 360 ​​Threat Intelligence Center - March 2019

Detection (one case): 94[.]23.148.194

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The MuddyWater "BlackWater" Campaign

Security researchers discovered a new cyberattack campaign in April 2019 dubbed "BlackWater." The attackers used malicious documents to secretly install a backdoor on victims' computers. They employed new, multi-step techniques specifically designed to bypass security controls and hide their activities.

Researchers believe with moderate confidence that a persistent threat group known as MuddyWater is behind this campaign. MuddyWater has been actively conducting cyber operations since at least November 2017 and is known for continuing its attacks even after being publicly exposed by security researchers.

The primary goal of the attack was to establish remote access to the victim's machine by installing a hidden backdoor. Once inside, the attackers focused on silently gathering identifying information about the computer and the network it belonged to, while carefully monitoring to see if security teams were investigating them.

While the exact number of victims is not specified, this campaign is part of a larger, ongoing series of operations. The threat actors continuously evolve their methods, indicating a sustained and committed effort to infiltrate their targets.

The group has a well-known history of primarily targeting organizations located in the Middle East, including entities based in Turkey. The attackers used a fake document titled "company information list.doc" to trick victims, suggesting they were aiming at corporate or professional personnel.

The attack likely began with a deceptive phishing email containing a malicious document. When a user opened the document and enabled its features, a hidden script ran in the background to ensure the malware would survive computer restarts. Finally, it used built-in computer management tools to gather system details and quietly transmitted them back to the attackers over the internet.

The focus on Middle Eastern and Turkish entities aligns with MuddyWater's historical regional interests. Gaining remote access to corporate networks in these areas allows the attackers to maintain a hidden foothold for long-term intelligence gathering or future operations.

Organizations should be extremely cautious with email attachments, especially documents that ask users to enable macros or special features. Security teams should proactively hunt for the new hiding techniques used in this campaign, as standard automated security rules may not catch the attackers' disguised network traffic.

This appears to be a targeted issue driven by a specific, persistent threat group. The attackers are deliberately focusing on certain regional organizations and customizing their tools to evade detection at those specific locations.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights