Skip to content
IranState-SponsoredActiveMITRE G0069Malpedia ↗

MuddyWater

Iran's Ministry of Intelligence, named as such by U.S. Cyber Command. Runs espionage almost entirely on legitimate remote-management software.

Open MITRE Navigator layer ↗Download profile JSON
Active
2017–present
Motivation
Espionage
Aliases
11
Exploited CVEs
5
ATT&CK techniques
11
Cited sources
11

Overview

MuddyWater is the operational arm of Iran's Ministry of Intelligence and Security (MOIS), formally identified as such by U.S. Cyber Command in January 2022 — an unusually direct attribution from a military command.

Its defining tradecraft choice is the near-total avoidance of custom malware. Rather than deploying implants, the group installs legitimate commercial remote monitoring and management software — Atera, ScreenConnect, SimpleHelp, RemoteUtilities, Syncro — on victim machines. These are signed, reputable products that thousands of organisations run legitimately. Antivirus does not flag them, EDR does not alert on them, and an analyst reviewing installed software sees a plausible IT tool. Everything that follows happens over an approved, encrypted commercial channel.

Delivery is correspondingly simple: phishing from compromised legitimate mailboxes at real organisations, often ones the group breached earlier in the same campaign, so the sender's reputation and domain are genuine.

Targeting spans government, telecommunications, energy, and defence across the Middle East, with regular reach into Europe, North America, and Asia. Israeli and Gulf state targets have featured heavily, and activity against Israeli organisations increased sharply after October 2023.

The group has also been used as a delivery layer for more aggressive Iranian operations — several intrusions that began as MuddyWater access ended in ransomware or hack-and-leak conducted by related clusters.

Attribution

Down to the named unit where public evidence supports it.

IranMOIS — Ministry of Intelligence and SecurityConfirmed

U.S. Cyber Command publicly identified MuddyWater as a subordinate element within Iran's Ministry of Intelligence and Security in January 2022, releasing malware samples to VirusTotal alongside the statement. The attribution was corroborated by a joint advisory from CISA, FBI, NSA, U.S. Cyber Command CNMF, and UK NCSC the following month.

Attributing sources

Cross-vendor naming crosswalk

11 designators across 10 organisations.

MITRE ATT&CK

index ↗
  • MuddyWater

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Mango SandstormFormerly MERCURY
  • MERCURYRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Static Kitten

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • TEMP.Zagros

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • COBALT ULSTER

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Boggy Serpens

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Kaspersky GReAT

index ↗
  • SeedwormAlso used by Symantec

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Earth Vetala

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

Symantec (Broadcom)

index ↗
  • Seedworm

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • MuddyWater / MOIS

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

IsraelSaudi ArabiaTürkiyeUnited Arab EmiratesJordanIraqEgyptUnited StatesIndiaPakistanAzerbaijan

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

PowGooploader

DLL loader masquerading as a Google Update component, decrypting and running PowerShell stages.

SmallSievebackdoor

Python backdoor using the Telegram API for C2, released publicly by U.S. Cyber Command.

MuddyC2Goframework

Go-based command-and-control framework replacing earlier PowerShell-centric infrastructure.

Shared, commodity & living-off-the-land

Atera Agentutility

Legitimate commercial RMM software installed as the primary access mechanism — signed, reputable, and invisible to antivirus.

ScreenConnect / SimpleHelputility

Additional commercial remote-support tools used interchangeably as backup access channels.

Ligoloutility

Open-source reverse tunnelling tool used for pivoting into internal networks.

chiselutility

Open-source TCP/UDP tunnel over HTTP for traversing network boundaries.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by MuddyWater
CVE-2022-47966KEVransomware9.81 Jan 2023Zoho ManageEngine unauthenticated RCE exploited for initial access to enterprise networks.SRCUnit 42
CVE-2021-44228KEVransomware10.01 Jan 2022Log4Shell exploited against internet-facing Java applications, including SysAid servers at Israeli targets.SRCMicrosoft Threat Intelligence
CVE-2021-34473KEVransomware9.81 Oct 2021ProxyShell chain exploited for Exchange access at regional government and telecom targets.SRCCISA and partners
CVE-2020-1472KEVransomware10.01 Oct 2020Zerologon used for rapid domain controller compromise after initial foothold.SRCCISA and partners
CVE-2020-0688KEVransomware8.81 May 2020Exchange static validation key exploited for authenticated remote code execution as SYSTEM on mail servers.SRCCISA and partners

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 11 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
11 techniques across 6 tactics · 6 with actor-specific notes

Campaign timeline

  1. Israeli Organisation Targeting

    Sharply increased operations against Israeli government, technology, and academic organisations following October 2023, using compromised legitimate mailboxes for delivery and commercial remote monitoring software for access.

    CVE-2021-44228GovernmentTechnologyTelecommunicationsEducation

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.