Threat group.View on attack.mitre.org
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
MuddyWater has performed credential dumping with Mimikatz and procdump64.exe. |
| T1003.004 LSA Secrets |
MuddyWater has performed credential dumping with LaZagne. |
| T1003.005 Cached Domain Credentials |
MuddyWater has performed credential dumping with LaZagne. |
| T1016 System Network Configuration Discovery |
MuddyWater has used malware to collect the victim’s IP address and domain name. |
| T1027.003 Steganography |
MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg. |
| T1027.004 Compile After Delivery |
MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code. |
| T1027.010 Command Obfuscation |
MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1033 System Owner/User Discovery |
MuddyWater has used malware that can collect the victim’s username. |
| T1036.005 Match Legitimate Resource Name or Location |
MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender. |
| T1041 Exfiltration Over C2 Channel |
MuddyWater has used C2 infrastructure to receive exfiltrated data. |
| T1047 Windows Management Instrumentation |
MuddyWater has used malware that leveraged WMI for execution and querying host information. |
| T1049 System Network Connections Discovery |
MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine. |
| T1053.005 Scheduled Task |
MuddyWater has used scheduled tasks to establish persistence. |
| T1057 Process Discovery |
MuddyWater has used malware to obtain a list of running processes on the system. |
| T1059.001 PowerShell |
MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.