ATT&CKGroupsMuddyWater

MuddyWater

G0069

Threat group.View on attack.mitre.org

About this group

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.

Techniques used68

Procedure examples68

TechniqueProcedure example
T1003.001
LSASS Memory

MuddyWater has performed credential dumping with Mimikatz and procdump64.exe.

T1003.004
LSA Secrets

MuddyWater has performed credential dumping with LaZagne.

T1003.005
Cached Domain Credentials

MuddyWater has performed credential dumping with LaZagne.

T1016
System Network Configuration Discovery

MuddyWater has used malware to collect the victim’s IP address and domain name.

T1027.003
Steganography

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.

T1027.004
Compile After Delivery

MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.

T1027.010
Command Obfuscation

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1033
System Owner/User Discovery

MuddyWater has used malware that can collect the victim’s username.

T1036.005
Match Legitimate Resource Name or Location

MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.

T1041
Exfiltration Over C2 Channel

MuddyWater has used C2 infrastructure to receive exfiltrated data.

T1047
Windows Management Instrumentation

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1049
System Network Connections Discovery

MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine.

T1053.005
Scheduled Task

MuddyWater has used scheduled tasks to establish persistence.

T1057
Process Discovery

MuddyWater has used malware to obtain a list of running processes on the system.

T1059.001
PowerShell

MuddyWater has used PowerShell for execution.

View all 68 procedure examples

Software21

Campaigns0

None recorded.

References13

  1. CYBERCOM Iranian Intel Cyber January 2022 Open source
    Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.
  2. ClearSky MuddyWater June 2019 Open source
    ClearSky. (2019, June). Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal. Retrieved May 14, 2020.
  3. ClearSky MuddyWater Nov 2018 Open source
    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.
  4. DHS CISA AA22-055A MuddyWater February 2022 Open source
    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.
  5. ESET_MuddyWater_Dec2025 Open source
    ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.
  6. FalconFeeds_Iran_Mar2026 Open source
    FalconFeeds.io. (2026, March 5). The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict. Retrieved March 9, 2026.
  7. Huntio_IranInfra_Mar2026 Open source
    Hunt.io. (2026, March 4). Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation. Retrieved April 16, 2026.
  8. NaumaanProofpoint_GlobalClickFix_April2025 Open source
    Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.
  9. Reaqta MuddyWater November 2017 Open source
    Reaqta. (2017, November 22). A dive into MuddyWater APT targeting Middle-East. Retrieved May 18, 2020.
  10. Symantec MuddyWater Dec 2018 Open source
    Symantec DeepSight Adversary Intelligence Team. (2018, December 10). Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms. Retrieved December 14, 2018.
  11. SymantecCarbonBlack_Seedworm_Mar2026 Open source
    Threat Hunter Team. (2026, March 5). Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company. Retrieved March 5, 2026.
  12. Talos MuddyWater Jan 2022 Open source
    Malhortra, A and Ventura, V. (2022, January 31). Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables. Retrieved June 22, 2022.
  13. Unit 42 MuddyWater Nov 2017 Open source
    Lancaster, T.. (2017, November 14). Muddying the Water: Targeted Attacks in the Middle East. Retrieved March 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.