Skip to main content

MuddyWater

Repository Navigation

Background

MuddyWater has been active since approximately 2017, and is one of the most consistently documented Iranian cyber espionage groups in public reporting. CISA explicitly stated in advisory AA22-055A that MuddyWater is "a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS)," making it one of the few Iranian actors with firm organizational attribution in a U.S. government advisory. The group targets government, local government, telecommunications, defense, and oil and gas organizations across the Middle East, Europe, Asia, and North America.

The group's operational evolution is well-documented. Early campaigns (2017–2019) relied on POWERSTATS — a PowerShell-based backdoor — distributed through malicious macro-embedded Office documents. By 2020–2022, MuddyWater shifted toward living-off-the-land approaches using PowerSploit, Empire, Koadic, and legitimate remote access tools. From 2022 onward, the group substantially expanded its abuse of commercial remote monitoring and management (RMM) tools — including Atera, ConnectWise, AnyDesk, and RemoteUtilities — delivered via phishing emails to serve as persistent C2 channels without deploying custom malware.

Two developments mark MuddyWater's 2023–2025 trajectory. First, Check Point's July 2024 BugSleep analysis documented a new custom implant replacing RMM abuse in some operations, with modular task-based execution and direct C2. Second, Microsoft attributed the February 2023 Technion University incident to MERCURY (the retired MuddyWater designator) acting together with DEV-1084 (Storm-1084) — a destructive affiliate that deployed the DarkBit ransomware persona. This indicates MuddyWater-linked activity can precede or enable destructive operations conducted by associated subgroups, not only persistent espionage.

For Israeli government defenders, the Israel National Cyber Directorate (INCD) issued a MuddyWater-specific advisory in 2024 documenting campaigns against Israeli entities using phishing and RMM tool abuse, making this the highest-confidence Israeli-targeting documentation in the primary source set.

Aliases: Mango Sandstorm, Boggy Serpens (Microsoft, current), Static Kitten, Seedworm, MERCURY (Microsoft, retired April 2023), TEMP.Zagros, TA450 (Proofpoint), Earth Vetala (Trend Micro).

Assessed sponsor: Iran MOIS-aligned in public reporting.

Relevance

MuddyWater is high priority for Israeli government and regional public-sector defense because MITRE records targeting of government, local government, telecommunications, defense, and oil and gas organizations across the Middle East and other regions.

Defensive Focus

  • Spearphishing and malicious document delivery.
  • PowerShell execution and script-based collection.
  • Legitimate remote access tool abuse.
  • Credential collection and lateral movement preparation.

Field Manual Cross-Reference

Full public-source case study with PIR/SIR decomposition, alias table, sponsor assessment, ATT&CK mapping with quality levels, telemetry requirements, and DRL-1 hunt hypotheses: CTI Analyst Field Manual — MuddyWater Worked Example.

Detection Ideas

  • RMM execution from user download folders.
  • PowerShell encoded commands launched by Office, browser, archive, or script-host processes.
  • New persistence from suspicious scheduled tasks or registry run keys.

Sources: SRC-MITRE-G0069, SRC-CISA-AA22-055A, SRC-INCD-MUDDYWATER-2024, SRC-INCD-MUDDYWATER-PHISHING, SRC-ESET-MUDDYWATER-SNAKES, SRC-CP-BUGSLEEP, SRC-KASPERSKY-ICS-Q4-2025, SRC-BRANDEFENSE-MUDDYWATER-2025, SRC-AP-MUDDYWATER.

Source note: Kaspersky ICS and Brandefense are Score B synthesis sources in this repository. Use them for collection planning and cross-checking, then anchor high-impact claims to ESET, INCD, CISA, MITRE, or Check Point.

Public Reports

Own ecosystem — read first:

Government advisories:

  • CISA Advisory AA22-055A — MuddyWater — CISA/CNMF/NCSC-UK/DC3, February 2022. Establishes MOIS attribution, describes TTPs, and provides IOCs. Source ID SRC-CISA-AA22-055A.
  • INCD MuddyWater Advisory 2024 — Israel National Cyber Directorate. Israeli-facing campaign documentation with IOCs and phishing infrastructure. Source ID SRC-INCD-MUDDYWATER-2024.

MITRE ATT&CK:

Primary vendor reporting:

  • Check Point Research, "BugSleep: A New MuddyWater Backdoor" — July 2024. Analysis of post-RMM custom implant. Source ID SRC-CP-BUGSLEEP.
  • ESET Research, "MuddyWater: New Snakes in the Mud" — Technical analysis of updated toolset and campaign evolution. Source ID SRC-ESET-MUDDYWATER-SNAKES.
  • Microsoft MSTIC, "MERCURY and DEV-1084: Destructive Attack on Hybrid Environment" — April 2023. Documents MuddyWater/Storm-1084 joint destructive operation. Source ID SRC-MS-MERCURY-DEV1084-2023.