MuddyWater is an Iranian state-sponsored cyberespionage group associated with the Ministry of Intelligence and Security (MOIS). It has been active since at least 2017 and is widely tracked under aliases including Static Kitten, Seedworm, TEMP.Zagros, Boggy Serpens, Earth Vetala, and Mercury. The group primarily targets government, diplomatic, telecommunications, defense, and oil and natural gas organizations, with a strong concentration on the Middle East and North Africa but activity also observed across Asia, Europe, North America, and Africa. MuddyWater is known for espionage-driven intrusions conducted through spearphishing and exploitation of vulnerabilities, often followed by deployment of custom backdoors and remote access tooling. Reported malware and tooling associated with the group include the Phoenix backdoor, FakeUpdate loader, UDPGangster, PowerShell-based implants, and Android surveillance malware such as DCHSpy. Recent reporting has described campaigns against embassies, diplomatic missions, foreign ministries, and consulates, including large-scale operations affecting more than 100 government entities in the Middle East and North Africa. The group demonstrates broad post-compromise capability, including persistence, credential theft, data exfiltration, remote shell access, and use of legitimate remote management tools for operational support. Phoenix v4 has been reported with enhanced persistence, including COM-based mechanisms, while associated credential-stealing components have targeted Chromium-based browser data. MuddyWater has also operated mobile surveillance campaigns, distributing Android spyware through fake VPN-themed lures shared over messaging platforms; these implants have been reported to steal contacts, messages, audio, WhatsApp data, and to access device microphones and cameras. MuddyWater’s operations are consistently characterized as cyberespionage in support of Iranian state interests. The group has also been linked to broader MOIS activity that prompted sanctions against Iran’s intelligence ministry. Its targeting of public-sector and diplomatic entities, combined with repeated use of phishing, custom malware, and surveillance tooling, makes it one of the most prominent Iranian intelligence-linked intrusion sets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MuddyWater is an Iranian APT group known for cyber-espionage and delivering custom malware such as UDPGangster.
TEMP.Zagros used Gemini LLM for malware development and data analysis, employing social engineering to bypass AI safeguards and obtain technical assistance for custom malware projects.
MuddyWater is engaged in espionage campaigns, expanding its toolkit with the Phoenix v4 backdoor delivered via FakeUpdate, abusing remote management tools, deploying a custom Chromium credential stealer, and using NordVPN for phishing operations. They are also using COM-based persistence and maintaining live command and control infrastructure.
MuddyWater is an Iranian state-sponsored threat actor known for conducting espionage and disruptive cyber operations, primarily targeting government entities and critical infrastructure in the Middle East, North Africa, and occasionally Europe. The group is linked to Iran's Ministry of Intelligence and Security (MOIS) and has been responsible for high-profile attacks, including the disruption of Albanian government services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.