A joint U.S.-U.K. advisory warned that the Iran-linked APT group MuddyWater, tied to Iran’s Ministry of Intelligence and Security, is targeting government and private-sector organizations across Asia, Africa, Europe, and North America. The campaign has hit sectors including telecommunications, defense, local government, and oil and natural gas, with operators using spear-phishing, exploitation of known Microsoft flaws such as CVE-2020-1472 and CVE-2020-0688, open-source tooling, and a broad malware arsenal including PowGoop, Small Sieve, Canopy/Starwhale, Mori, and POWERSTATS for delivery, persistence, command and control, and data theft.
The warning aligns with years of reporting that MuddyWater has run espionage operations using macro-laced lure documents, staged PowerShell payloads, LOLBins such as rundll32.exe and mshta.exe, scheduled tasks, and compromised domains to infect targets in the Middle East and beyond, including Lebanon and Oman. Researchers have also linked the group to more disruptive activity, including the DarkBit ransomware campaign, indicating that MuddyWater’s operations now span both intelligence collection and destructive or coercive attacks; agencies urged organizations to strengthen cyber hygiene, patch exposed systems, and apply tighter application controls to reduce risk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
K7 Labs analyzed a DarkBit ransomware campaign attributed to MuddyWater, describing an infection chain using an ISO lure, a disguised shortcut, PrintBrm.exe, and a Cobalt Strike beacon before deployment of the ransomware payload.
ClearSky reported a MuddyWater espionage campaign targeting likely victims in Lebanon and Oman across government, academia, cryptocurrency, telecommunications, and oil, using macro-laced lures and a two-stage infection chain that deployed POWERSTATS.
Researchers observed a large volume of MuddyWater spear-phishing documents throughout 2018, with activity escalating from May onward, targeting government, military, telecommunications, and educational entities across the Middle East and beyond.
A joint U.S.-U.K. advisory said MuddyWater has conducted broad cyber campaigns in support of Iran's Ministry of Intelligence and Security objectives since 2018.
Kaspersky observed MuddyWater in 2017 using spear-phishing against government agencies, military institutions, telecommunications companies, and universities in the Middle East.
A joint advisory from U.K. and U.S. agencies warned that MuddyWater was targeting government and private-sector organizations across Asia, Africa, Europe, and North America, including telecommunications, defense, local government, and oil and natural gas.
Government agencies observed MuddyWater exploiting the Microsoft Netlogon vulnerability CVE-2020-1472 and Microsoft Exchange vulnerability CVE-2020-0688 to access sensitive government and commercial networks.
Microsoft published a Security Update Guide entry for CVE-2020-0688, a Microsoft Exchange vulnerability later cited as exploited by MuddyWater.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
inforisktoday.com
Open sourcesecurelist.com
Open sourcelabs.k7computing.com
Open sourcecisa.gov
Open sourceclearskysec.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.