G0069 · 59 ATT&CK techniques · 36 correlated reports

MuddyWater

Aliases: Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.

Open interactive actor investigation

ATT&CK techniques

T1566.002
Spearphishing Link
T1137.001
Office Template Macros
T1574.002
DLL Side-Loading
T1588.002
Tool
T1218.005
Mshta
T1047
Windows Management Instrumentation
T1003.004
LSA Secrets
T1566.001
Spearphishing Attachment
T1559.001
Component Object Model
T1059.003
Windows Command Shell
T1218.003
CMSTP
T1036.005
Match Legitimate Name or Location
T1562.001
Disable or Modify Tools
T1087.002
Domain Account
T1059.007
JavaScript
T1583.006
Web Services
T1059.005
Visual Basic
T1016
System Network Configuration Discovery
T1547.001
Registry Run Keys / Startup Folder
T1140
Deobfuscate/Decode Files or Information
T1559.002
Dynamic Data Exchange
T1027.010
Command Obfuscation
T1027.004
Compile After Delivery
T1518.001
Security Software Discovery
T1074.001
Local Data Staging
T1113
Screen Capture
T1071.001
Web Protocols
T1518
Software Discovery
T1083
File and Directory Discovery
T1548.002
Bypass User Account Control
T1105
Ingress Tool Transfer
T1573.001
Symmetric Cryptography
T1555.003
Credentials from Web Browsers
T1560.001
Archive via Utility
T1059.006
Python
T1049
System Network Connections Discovery
T1082
System Information Discovery
T1555
Credentials from Password Stores
T1057
Process Discovery
T1132.001
Standard Encoding
T1104
Multi-Stage Channels
T1204.001
Malicious Link
T1027.003
Steganography
T1003.001
LSASS Memory
T1053.005
Scheduled Task
T1090.002
External Proxy
T1204.002
Malicious File
T1033
System Owner/User Discovery
T1219
Remote Access Software
T1041
Exfiltration Over C2 Channel
T1059.001
PowerShell
T1102.002
Bidirectional Communication
T1218.011
Rundll32
T1552.001
Credentials In Files
T1190
Exploit Public-Facing Application
T1210
Exploitation of Remote Services
T1203
Exploitation for Client Execution
T1003.005
Cached Domain Credentials
T1589.002
Email Addresses

Correlated CTI and IR reports

MuddyWater G0069
MITRE ATT&CK · direct source mapping
Stryker Handala MOIS and MuddyWater: Full Kill Chain and Unified Detection Pack v3
ThreatHunter.ai · direct source mapping
MuddyWater: Snakes by the riverbank
ESET Research · actor reference
New BugSleep Backdoor Deployed in Recent MuddyWater Campaigns
Check Point Research · actor reference
Overview of Recent Phishing
Israel National Cyber Directorate · actor reference
Unmasking: Technological Advancement and Evolution of MuddyWater in 2024
Israel National Cyber Directorate · actor reference
CTI Research: MuddyWater/Seedworm Mango Sandstorm
Andrey Pautov · actor reference
1. Executive Summary
Israel Threat Actors CTI · explicit report mention
Actor Deep Research Prompts
Israel Threat Actors CTI · explicit report mention
Andrey Pautov Medium Articles
Israel Threat Actors CTI · explicit report mention
Blue-Team IOC Tables — Consolidated
1200km CTI repository · explicit report mention
CTI
1200km CTI repository · explicit report mention
CTI Research Template
1200km CTI repository · explicit report mention
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
Cyber Threat Intelligence Dossier: Iranian and Hamas-Aligned Operations Targeting Israeli and Allied Ecosystems (2023-2026)
Israel Threat Actors CTI · explicit report mention
Defensive CTI Research on Threats to Israeli Government and Public-Sector Environments
Israel Threat Actors CTI · explicit report mention
Defensive Cyber Threat Intelligence Report: Israeli Critical Infrastructure and Geopolitical Escalation (2024-2026)
Israel Threat Actors CTI · explicit report mention
IOC Tables — MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
Israel Government Threat Actors CTI: Evidentiary Foundation Intake
Israel Threat Actors CTI · explicit report mention
MuddyWater / Seedworm
CTI Analyst Field Manual · explicit report mention
Release Notes
Israel Threat Actors CTI · explicit report mention
Report Index
Israel Threat Actors CTI · explicit report mention
Research Intake Upgrade Summary
Israel Threat Actors CTI · explicit report mention
Worked Cases
Israel Threat Actors CTI · explicit report mention
CTI Analyst Field Manual Complete Reference
1200km Medium · authored report mention
CTI Led Defensive Strategy for a Cellular Provider Case Study
1200km Medium · authored report mention
CTI Research MuddyWater Seedworm Mango Sandstorm
1200km Medium · authored report mention
Boggy Serpens Threat Assessment
Unit 42 · actor context
Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks
CISA · actor context
Iranian Government-Sponsored Threat Actor MuddyWater
Israel National Cyber Directorate · actor context
Iranian MOIS Actors and the Cyber Crime Connection
Check Point Research · actor context
MERCURY and DEV-1084: Destructive attack on hybrid environment
Microsoft Security · actor context
APT and financial attacks on industrial organizations in Q4 2025
Kaspersky ICS CERT · actor context
MuddyWater APT 2025
Brandefense · actor context

Continue the investigation