Iranian APT MERCURY Exploits Zerologon in Persistent Cyber Campaigns
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Vulnerability Exploitation
- Attack Complexity: Very High
- Threat Risk: High Impact/Low Probability
Threat Overview
Microsoft reports that the Iranian APT group MERCURY (aka MuddyWater) is actively exploiting the Zerologon vulnerability (CVE-2020-1472) to compromise Active Directory services. Known for targeting Middle Eastern governments for data exfiltration, MERCURY has also exploited the SharePoint vulnerability (CVE-2019-0604) to implant web shells for persistent access. These attacks often involve Cobalt Strike payloads and lateral movement within networks, focusing on domain controllers. Despite patches released in 2020, exploitation attempts remain widespread, highlighting the need for robust patch management. MERCURY's activities highlight the ongoing threat to governments and other critical sectors in the Middle East.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Middle East Countries | High |
Exploited Vulnerabilities
About Affiliation
Mango Sandstorm
Mango Sandstorm is Microsoft's current designation for the Iranian MOIS-linked threat cluster widely known as MuddyWater. Active since at least 2017, the group targets government, telecommunications, defense, and energy organizations across the Middle East and beyond. Microsoft has documented Mango Sandstorm's use of legitimate remote administration tools alongside custom malware for persistent access, and its collaboration with the Storm-1084 subgroup in destructive operations against Israeli organizations. The Mango Sandstorm name replaced the earlier Mercury designation as part of Microsoft's 2023 threat actor naming taxonomy update.
View Mango Sandstorm's Insights