ThreatBox · Threat Actor Attribution
MuddyWater
a.k.a. Static Kitten, MERCURY, TEMP.Zagros, Mango Sandstorm
Espionage (state-sponsored) Iran (MOIS — Ministry of Intelligence and Security) First seen 2017
MuddyWater is an Iranian MOIS-attributed espionage group operating primarily across the Middle East and neighbouring regions. Heavy use of PowerShell (POWERSTATS / POWGOOP) and legitimate remote-monitoring tools (ScreenConnect, Atera, RemoteUtilities) to blend in. Post-2022 they have partnered with DEV-1084/DarkBit for destructive operations against Israeli targets.
Targeted sectors
GovernmentTelecomOil & gasDefense
Targeted regions
Middle EastCentral AsiaEuropeNorth America
Known TTPs (3)
T1059.001PowerShell
T1219Remote Access Software (ScreenConnect, Atera)
T1566.001Spearphishing Attachment
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2017-11First public reporting by Palo Alto Unit 42
- 2022-02US CYBERCOM public attribution to Iranian MOIS
- 2023-04Joint destructive campaign with DEV-1084 (DarkBit wiper) on Israeli education
References
End of dossier · MuddyWater
Back to ThreatBox