Threats Feed|MuddyWater|Last Updated 04/06/2026|AuthorCertfa Radar|Publish Date07/01/2020

Muddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Malicious Macro,Trojan,Phishing,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Muddy Water threat actor, suspected to be a continuation of the previously reported BlackWater campaign, has been observed distributing malicious documents via spearphishing emails. One document focuses on the nomination of Stephen Moore to the Federal Reserve, likely leveraging current events for social engineering. Another targets the oil and gas sector and features a malicious macro named "H3OpAirStrike," potentially referencing historical Iranian air strikes. Both macros communicate with C2 servers and deploy PowerShell trojans. The malware collects various workstation data and uses Invoke-Obfuscation to evade detection.

Detected Targets

TypeDescriptionConfidence
SectorOil and Gas
Verified
RegionUnited States
Medium

Extracted IOCs

  • accesemailaccount[.]tk
  • account-signin-secure[.]com
  • accounts-login[.]ga
  • accountslogin[.]ga
  • accounts-login[.]gq
  • apikeyallervice[.]business
  • apikeyallervice[.]com
  • loginaccounts[.]cf
  • login-accounts[.]gq
  • logind2-secure[.]tk
  • login-dc2-verifyaccounts[.]ga
  • login-dc2-verifyaccounts[.]tk
  • login-secure-account[.]cf
  • login-secure-account[.]gq
  • login-secure-account[.]ml
  • roadtosultan1[.]org
  • secure-login-accounts[.]gq
  • signin-secure[.]tk
  • reauth92-services.sytes[.]net
  • service0auht-center.ddns[.]net
  • 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1
  • 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce
  • f327abed77b4b19b4471eaebf722295b8e50a47f36a4d7662cac91b1a622e64a
  • f779ccc3da9d8c62a9596c3567b38cabfa1b1292129c1a77db67aaffb7828fe2
  • 104[.]237.255.195
  • 194[.]187.249.78
  • 38[.]132.99.167
  • 91[.]132.139.159
  • 91[.]132.139.194
  • 91[.]132.139.196
  • hxxp://104[.]237.255.195/p[.]txt
  • hxxp://194[.]187.249.78/
  • hxxp://38[.]132.99.167/crf[.]txt
  • hxxp://91[.]132.139.196/prxy[.]php?rcecms=h3opairstrike
download

Tip: 34 related IOCs (6 IP, 20 domain, 4 URL, 0 email, 4 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater's Sophisticated Cyber Operations Target Geopolitical Foes in Asia and the Middle East

Source: Trend Micro - June 2019

Detection (four cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt, 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1, 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce

MuddyWaterBlackWater Campaign: MuddyWater's Advanced Evasion and Persistence Techniques

Source: Rewterz - May 2019

Detection (two cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt

MuddyWaterMuddyWater's BlackWater: An In-depth Look at Advanced TTPs

Source: Cisco Talos - May 2019

Detection (two cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Understanding the "Summer Mirage" Cyber Campaign

Security researchers uncovered a cyber espionage campaign dubbed "Summer Mirage". Threat actors used malicious documents and fake login websites to compromise workstations and harvest user credentials.

The campaign is attributed with high confidence to Muddy Water, an Iran-nexus threat group. They have been recognized as an active persistent threat actor since at least November 2017.

The attackers sought to deploy a fully functional remote access trojan on victim computers to gain interactive control over the infected systems. A secondary goal was to harvest end-user credentials via typo-squatted domains that mimicked authentic login services.

The campaign was highly targeted rather than widespread. The threat actors utilized tailored, sector-specific subject matter to infiltrate specialized networks.

Yes, the attackers targeted individuals tracking Stephen Moore's Federal Reserve appointment. They also heavily targeted members of the oil and gas vertical, specifically companies focused on extracting and processing crude oil.

Attackers sent deceptive documents that required victims to enable macros to view the content. Once enabled, these macros downloaded a hidden trojan from an attacker-controlled server to compromise the machine.

While explicit motivations are not detailed, the targeting aligned with the threat group's historical targeting trends and the specific political or industrial subject matter of the documents. Additionally, previously compromised networks in these sectors were noted to be particularly vulnerable to these attacks.

Organizations must thoroughly update their email filters and end-point antivirus solutions. Crucially, employees must be trained to never enable macros on documents sent from unknown or untrusted sources.

This is a carefully targeted campaign aimed at specific verticals and political interests, rather than a widespread attack on the general public.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights