PhonyC2 is a custom command-and-control framework associated with the Iranian espionage group MuddyWater, also tracked as Seedworm and several other aliases. It formed part of the group’s long-running intrusion toolkit used in cyberespionage operations against sectors including government, telecommunications, oil and gas, education, and other organizations across the Middle East, Central Asia, Africa, and North America. Public reporting indicates MuddyWater used PhonyC2 prior to transitioning to the newer Go-based MuddyC2Go infrastructure, with the shift assessed to have occurred after PhonyC2 source code leaked in 2023.
PhonyC2 functioned as attacker-controlled command-and-control infrastructure for post-compromise operations. It was used alongside MuddyWater’s broader ecosystem of PowerShell-based tradecraft, remote administration tools, credential access utilities, proxying tools, and publicly available offensive frameworks. Campaigns linked to MuddyWater commonly relied on spearphishing and phishing lures, including archive-based delivery and macro-enabled documents, after which operators used legitimate remote management software or scripted payloads to establish access and execute follow-on activity. Within that operational model, PhonyC2 supported command delivery and ongoing control of compromised systems.
The framework is most strongly tied to Windows-centric intrusions because MuddyWater’s observed infection chains and post-exploitation activity around this tooling heavily used PowerShell and Windows administration mechanisms. Reporting does not provide high-confidence evidence here for PhonyC2’s internal implementation details beyond its role as a custom C2 framework, nor for a broader cross-platform scope. PhonyC2 is best understood as a MuddyWater-specific back-end control component that enabled persistent operator interaction during espionage intrusions before being superseded by MuddyC2Go.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In June 2023, we published a report about PhonyC2, a custom C2 framework used by the MuddyWater APT group ... MuddyWater seems to have stopped using PhonyC2 and is now using MuddyC2Go instead
6 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious program in MuddyWater's arsenal used for command-and-control purposes.
Seedworm's previous command-and-control infrastructure, reportedly replaced by MuddyC2Go after its source code leaked in 2023.
A custom Python-based command-and-control framework previously used by MuddyWater and later apparently replaced by MuddyC2Go after its source code leaked.
A command-and-control framework previously used by MuddyWater for post-compromise communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.