Initial Access
2 techniques·derived
Sent from compromised legitimate mailboxes at real organisations. Exchange, Log4Shell, and Zoho ManageEngine.
Iran's Ministry of Intelligence, named as such by U.S. Cyber Command. Runs espionage almost entirely on legitimate remote-management software.
MuddyWater is the operational arm of Iran's Ministry of Intelligence and Security (MOIS), formally identified as such by U.S. Cyber Command in January 2022 — an unusually direct attribution from a military command.
Its defining tradecraft choice is the near-total avoidance of custom malware. Rather than deploying implants, the group installs legitimate commercial remote monitoring and management software — Atera, ScreenConnect, SimpleHelp, RemoteUtilities, Syncro — on victim machines. These are signed, reputable products that thousands of organisations run legitimately. Antivirus does not flag them, EDR does not alert on them, and an analyst reviewing installed software sees a plausible IT tool. Everything that follows happens over an approved, encrypted commercial channel.
Delivery is correspondingly simple: phishing from compromised legitimate mailboxes at real organisations, often ones the group breached earlier in the same campaign, so the sender's reputation and domain are genuine.
Targeting spans government, telecommunications, energy, and defence across the Middle East, with regular reach into Europe, North America, and Asia. Israeli and Gulf state targets have featured heavily, and activity against Israeli organisations increased sharply after October 2023.
The group has also been used as a delivery layer for more aggressive Iranian operations — several intrusions that began as MuddyWater access ended in ransomware or hack-and-leak conducted by related clusters.
Down to the named unit where public evidence supports it.
U.S. Cyber Command publicly identified MuddyWater as a subordinate element within Iran's Ministry of Intelligence and Security in January 2022, releasing malware samples to VirusTotal alongside the statement. The attribution was corroborated by a joint advisory from CISA, FBI, NSA, U.S. Cyber Command CNMF, and UK NCSC the following month.
Attributing sources
11 designators across 10 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
DLL loader masquerading as a Google Update component, decrypting and running PowerShell stages.
Python backdoor using the Telegram API for C2, released publicly by U.S. Cyber Command.
Go-based command-and-control framework replacing earlier PowerShell-centric infrastructure.
Shared, commodity & living-off-the-land
Legitimate commercial RMM software installed as the primary access mechanism — signed, reputable, and invisible to antivirus.
Additional commercial remote-support tools used interchangeably as backup access channels.
Open-source reverse tunnelling tool used for pivoting into internal networks.
Open-source TCP/UDP tunnel over HTTP for traversing network boundaries.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by MuddyWater | ||
|---|---|---|---|---|
| CVE-2022-47966KEVransomware | 9.8 | Zoho ManageEngineZoho | 1 Jan 2023 | Zoho ManageEngine unauthenticated RCE exploited for initial access to enterprise networks.SRCUnit 42 ↗ |
| CVE-2021-44228KEVransomware | 10.0 | Apache Log4j2Apache | 1 Jan 2022 | Log4Shell exploited against internet-facing Java applications, including SysAid servers at Israeli targets.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2021-34473KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 Oct 2021 | ProxyShell chain exploited for Exchange access at regional government and telecom targets.SRCCISA and partners ↗ |
| CVE-2020-1472KEVransomware | 10.0 | Windows NetlogonMicrosoft | 1 Oct 2020 | Zerologon used for rapid domain controller compromise after initial foothold.SRCCISA and partners ↗ |
| CVE-2020-0688KEVransomware | 8.8 | Microsoft Exchange ServerMicrosoft | 1 May 2020 | Exchange static validation key exploited for authenticated remote code execution as SYSTEM on mail servers.SRCCISA and partners ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
Sent from compromised legitimate mailboxes at real organisations. Exchange, Log4Shell, and Zoho ManageEngine.
1 technique·derived
PowerShell.
1 technique·derived
Scheduled Task.
2 techniques·derived
Rundll32, Modify Registry.
1 technique·derived
LSASS Memory.
4 techniques·derived
Signature technique — legitimate commercial RMM as the primary C2 channel. OneDrive, Dropbox, and file-sharing services for staging. chisel and Ligolo for internal pivoting.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Sent from compromised legitimate mailboxes at real organisations
Exchange, Log4Shell, and Zoho ManageEngine
Sharply increased operations against Israeli government, technology, and academic organisations following October 2023, using compromised legitimate mailboxes for delivery and commercial remote monitoring software for access.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Curated links to the reports that established what is known about this group.