MuddyWater is a malware cluster and associated intrusion set widely linked to an Iranian state-aligned espionage actor active since at least 2017. The tooling is best known for Windows-focused backdoor activity implemented heavily in PowerShell and delivered through spearphishing campaigns that use macro-enabled Office documents with geopolitical decoys. Victims have included government, military, telecommunications, education, finance, and energy organizations, with a concentration in the Middle East and additional targeting in Europe and the United States.
Typical MuddyWater intrusion chains rely on user-enabled macros to launch staged scripts and living-off-the-land execution paths through trusted Windows components. Observed variants establish persistence through user-run startup mechanisms and scheduled execution, then launch obfuscated PowerShell payloads that perform host reconnaissance, collect system and network identity information, and communicate with command-and-control infrastructure for tasking. Reported command support includes screenshot capture, file upload, remote execution of additional stages, and system control actions such as reboot and shutdown. Some variants also disable Office security protections to facilitate follow-on document-based compromise.
The malware has shown consistent emphasis on defense evasion. Documented samples used layered obfuscation including encoding, encryption, and variable-name mangling, and abused Microsoft-signed binaries to blend malicious execution with legitimate system activity. Anti-analysis features have included checks for common debugging and monitoring tools, and some variants reportedly triggered system crashes when analysis environments were detected. Destructive functionality has also been observed, including a command capable of wiping multiple drives before rebooting the host.
MuddyWater has evolved over time with new loaders, backdoors, and command-and-control methods. More recent reporting has associated the actor with additional malware variants, including Rust-based tooling and the use of Telegram bots for command-and-control in operations affecting organizations in the Middle East and North Africa. Overall, MuddyWater is best characterized as a long-running espionage-oriented backdoor ecosystem that combines spearphishing, PowerShell-heavy post-compromise tradecraft, persistence, reconnaissance, and flexible remote tasking on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Below is a description of the malware extraction and execution flow, starting from the initial infection vector, running VBA code via a macro and then dropping the PowerShell code that establishes command-center communications, sends victim system information and then receives commands supported by the malware.
Fox Tempest’s operation — which included an authenticated portal and a drag-and-drop feature for rapid code signing — was directly linked to dozens of malware families, including Oyster, Lumma Stealer, MuddyWater, and Vidar.
Fox Tempest’s operation — which included an authenticated portal and a drag-and-drop feature for rapid code signing — was directly linked to dozens of malware families, including Oyster, Lumma Stealer, MuddyWater, and Vidar.
1 distinct technique documented for this family, organized by ATT&CK tactic.
The group operated as an enabler “upstream in the malware and ransomware supply chain” — not conducting attacks directly, but selling a malware-signing-as-a-service (MSaaS) offering that allowed cybercriminals to disguise malware as legitimate, trusted software. | The certificates allowed attackers to disguise malicious software as legitimate applications, helping malware bypass security filters.
124 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool family listed as deployed through Fox Tempest’s malware-signing service using fraudulent certificates.
A named malware/tooling family cited as linked to Fox Tempest’s fraudulent code-signing infrastructure.
Iran-nexus APT activity described as deploying multiple new malware components and using Telegram bots for C2 in a MENA-focused campaign.
A macro-delivered, multi-stage PowerShell backdoor used in espionage campaigns. It drops files into ProgramData, establishes persistence via HKCU Run or scheduled execution, disables Office protections, performs anti-analysis checks, registers the victim with C2 infrastructure, and supports commands including screenshot capture, payload execution via Excel/Outlook/Explorer, file upload/download, reboot, shutdown, and destructive cleaning of drives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.