> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
MUDDYWATER
/actor/muddywater/ · 0 intel reports
MuddyWater is an Iranian state-sponsored threat actor attributed to Iran's Ministry of Intelligence and Security (MOIS) by the US Cyber Command and multiple intelligence agencies. Active since at least 2017, the group conducts cyber espionage campaigns primarily targeting governments, military organisations, defence contractors, and telecommunications providers across the Middle East, Asia, Africa, Europe, and North America , reflecting a broad intelligence collection mandate serving Iranian strategic interests.
MuddyWater's attack methodology centres on spear-phishing campaigns delivering macro-embedded documents that deploy PowerShell-based malware frameworks , particularly their signature POWGOOP loader and SHARPSTATS implant. The group frequently updates and rotates their tooling to evade detection, and has demonstrated the ability to leverage legitimate remote administration tools including ScreenConnect, RemoteUtilities, and Syncro as post-exploitation access mechanisms.
The group has demonstrated particular focus on targeting Israeli and Saudi Arabian entities, reflecting the MOIS's intelligence priorities regarding Iran's primary regional adversaries. MuddyWater has also targeted Turkish government entities, likely related to intelligence collection on Turkish foreign policy and the activities of Iranian opposition groups operating from Turkey.
US Cyber Command publicly attributed MuddyWater to MOIS in January 2022 , an unusually direct and specific attribution from a military cyber command , and published several MuddyWater malware samples to VirusTotal simultaneously to assist defenders in detection. Despite this public exposure, MuddyWater has continued operations with limited disruption, demonstrating the resilience of well-resourced state intelligence cyber capabilities to public attribution pressure.
Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that MuddyWater executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.