Back to ThreatBox
ThreatBox · Threat Actor Attribution

MuddyWater

a.k.a. Static Kitten, MERCURY, TEMP.Zagros, Mango Sandstorm
Espionage (state-sponsored) Iran (MOIS — Ministry of Intelligence and Security) First seen 2017

MuddyWater is an Iranian MOIS-attributed espionage group operating primarily across the Middle East and neighbouring regions. Heavy use of PowerShell (POWERSTATS / POWGOOP) and legitimate remote-monitoring tools (ScreenConnect, Atera, RemoteUtilities) to blend in. Post-2022 they have partnered with DEV-1084/DarkBit for destructive operations against Israeli targets.

Targeted sectors
GovernmentTelecomOil & gasDefense
Targeted regions
Middle EastCentral AsiaEuropeNorth America

Known TTPs (3)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2017-11
    First public reporting by Palo Alto Unit 42
  2. 2022-02
    US CYBERCOM public attribution to Iranian MOIS
  3. 2023-04
    Joint destructive campaign with DEV-1084 (DarkBit wiper) on Israeli education

References

End of dossier · MuddyWater
Back to ThreatBox

Made with Emergent