MuddyWater — what to detect, and what we don’t know.

Gulf government and telecom, via the helpdesk tools your admins already trust.

68 techniques 16 detection behaviours 21 tools mapped Saudi Arabia, United Arab Emirates

Also tracked as  TEMP.Zagros · Static Kitten · Seedworm · MERCURY · COBALT ULSTER · G0069 · ATK51 · Boggy Serpens · Mango Sandstorm · TA450 · Earth Vetala · MUDDYCOAST

Attributed to
IR Iran (Islamic Republic of)
Gulf victimology
2 Saudi Arabia, United Arab Emirates
Techniques
68 across 14 tactics
Tooling
21 11 actor-specific · 10 commodity
Reporting
68 18 outlets · 31 research hosts

Summary

The short version

MuddyWater is a threat actor attributed to Iran (Islamic Republic of), assessed as espionage-motivated. Its recorded targeting runs to government across 9 countries in the open reporting we hold — Saudi Arabia, United Arab Emirates among them.

Across 68 attributed ATT&CK techniques we resolve 16 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are discovery command burst on one host and security tooling stopped, unloaded or blinded. Their toolkit is 21 named items: 11 we see only in this actor's reporting and 10 commodity or dual-use. That ratio is the point — the first group is what identifies them, the second is what they share with every other group and with red teams.

For a Gulf defender the relevant line is the victimology: Saudi Arabia, United Arab Emirates appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.

As MITRE describes them: “The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.” — MITRE ATT&CK, CC BY 4.0.

On the name. “MuddyWater” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.

02 — The detection plan

What to detect, ranked by what survives their retooling

Most actor profiles hand you indicators that expire in days. These are the behaviours the actor cannot drop without changing how they operate, each with the reason it holds. Weight is our own: how much of the actor's observed tradecraft the behaviour accounts for.

D2

Persistence pointing into world-writable staging

Tier 1–2

The persistence mechanism and the directory it points at both outlive the payload. The discriminator is the TARGET PATH, not the task or key name, which the actor can change freely.

8 techniques · weight 5

D3

Signed binary side-loading an unsigned library

Tier 1–3

The trusted executable is the constant; the dropped library changes every build. Detecting the LOAD relationship survives retooling that every hash and filename rule misses.

6 techniques · weight 5

D4

Credential access against LSASS

Tier 3–5

Few legitimate processes read LSASS memory, so precision is high in most estates once the agents that do are excluded.

2 techniques · weight 5

D5

User-facing application spawning an interpreter

Tier 3

The delivery wrapper changes constantly; an office, archive or browser process parenting a shell is the same shape across all of them.

8 techniques · weight 5

D8

Security tooling stopped, unloaded or blinded

Tier 3

Nothing legitimate disables the estate's own defences at endpoint scale, and the action reliably precedes the part of the intrusion you care about.

9 techniques · weight 5

D1

Sanctioned SaaS platform as command or exfil channel

Tier 5–6

Defeats egress-domain control outright — the destination is a platform the estate already permits, so no blocklist and no TLD heuristic will see it.

7 techniques · weight 4

D6

Credential store or keystroke capture

Tier 3

Kept separate from the LSASS rule because it needs different telemetry and tunes differently — a browser credential store read by a non-browser process is its own signal.

8 techniques · weight 4

D7

Vendor-suggestive name outside that vendor's paths

Tier 4

Encodes the naming RULE rather than the filenames, so it survives every rename. The convention is a habit; the names are inventory.

6 techniques · weight 4

D9

Encoded or obfuscated interpreter invocation

Tier 3

The command-line SHAPE — the flag combination, not the payload — is stable for months to years and cheap to match.

8 techniques · weight 4

D14

Execution brokered through WMI or a native API

Tier 3

Chosen to avoid a shell, so command-line rules miss it entirely. The broker is a stable choice; what it runs is not.

6 techniques · weight 4

D10

Living-off-the-land download of a second stage

Tier 5

The set of system binaries that can fetch a file is small and changes with the OS, not with the actor.

5 techniques · weight 3

D11

Collection staged into an archive before egress

Tier 3

Staging is a step the actor cannot skip, and it happens before the data leaves — the last cheap place to catch it.

7 techniques · weight 3

D12

Exploitation of an internet-facing service

Context

Not a durable behavioural signature but the entry vector for a large public estate — worth an exposure control even where the detection is weak.

3 techniques · weight 3

D13

Protocol tunnelling or an internal proxy hop

Tier 5

The tunneller is a tool choice that persists for months, and the traffic shape is visible even when the payload is not.

8 techniques · weight 3

D15

Beaconing to attacker infrastructure over web protocols

Tier 6–7

The URI shape and cadence are cheap to match and hold for weeks to months — but the destination itself rotates in days, so match the pattern rather than the host.

7 techniques · weight 3

D16

Discovery command burst on one host

Context

No single discovery command is worth an alert. The DENSITY is — several distinct recon binaries on one host inside an hour is a shape ordinary use does not produce.

17 techniques · weight 2

How to score it

No single behaviour here is worth waking someone. Summed weights of 6 on one host inside a window is an alert; 10 is an incident. The pair that most reliably means this actor rather than commodity crime is Persistence pointing into world-writable staging + Signed binary side-loading an unsigned library — seen together, treat as an incident regardless of total.

03 — Tooling

21 named tools, and what each is for

Purpose is derived, not asserted: each tool's own ATT&CK techniques are resolved to tactics, and the tactics it spends most of its techniques in are what it is for.

Actor-specific means we have no record of it outside this actor's reporting — those are the names that identify them. Commodity covers everything sold, published or shared: Cobalt Strike and Brute Ratel are licensed red-team software every pentester owns, Mimikatz and Impacket are public, and backdoors like ShadowPad circulate between unrelated groups. Finding a commodity tool tells you far less, which is exactly why the split is drawn. ATT&CK's own “malware vs tool” type answers a different question — whether the software is malicious — so it is not used for this.

Actor-specific — 11 items

POWERSTATS Actor-specific

Gathering data and moving data out.

S0223  ·  27 techniques  ·  Collection, Exfiltration, Execution
RustyWater Actor-specific

First access and staying resident.

S9037  ·  20 techniques  ·  Initial Access, Persistence, Stealth
MuddyViper Actor-specific

Gathering data and moving data out.

S9032  ·  18 techniques  ·  Collection, Exfiltration, Persistence
Tsundere Botnet Actor-specific

Moving data out and first access.

S9034  ·  17 techniques  ·  Exfiltration, Initial Access, Persistence
STARWHALE Actor-specific

Gathering data and staying resident.

S1037  ·  14 techniques  ·  Collection, Persistence, Exfiltration
Small Sieve Actor-specific

Staying resident and remote control.

S1035  ·  13 techniques  ·  Persistence, Command and Control, Stealth
LP-Notes Actor-specific

Gathering data and evading defences.

S9036  ·  11 techniques  ·  Collection, Stealth, Execution
Mori Actor-specific

Remote control and evading defences.

S1047  ·  9 techniques  ·  Command and Control, Stealth, Defense Impairment
PowGoop Actor-specific

Evading defences and remote control.

S1046  ·  8 techniques  ·  Stealth, Command and Control, Execution
Fooder Actor-specific

Evading defences and running code.

S9033  ·  7 techniques  ·  Stealth, Execution
SHARPSTATS Actor-specific

Network reconnaissance and remote control.

S0450  ·  7 techniques  ·  Discovery, Command and Control, Execution

Commodity and dual-use — 10 items

Empire Commodity

Credential theft and gathering data.

S0363  ·  73 techniques  ·  Credential Access, Collection, Persistence
PowerSploit Commodity

Credential theft and gathering data.

S0194  ·  28 techniques  ·  Credential Access, Collection, Persistence
Koadic Commodity

Gathering data and credential theft.

S0250  ·  27 techniques  ·  Collection, Credential Access, Lateral Movement
CrackMapExec Commodity

Credential theft and moving between hosts.

S0488  ·  20 techniques  ·  Credential Access, Lateral Movement, Discovery
Mimikatz Commodity

Credential theft and moving between hosts.

S0002  ·  17 techniques  ·  Credential Access, Lateral Movement, Persistence
LaZagne Commodity

Credential theft.

S0349  ·  10 techniques  ·  Credential Access
Rclone Commodity

Moving data out and gathering data.

S1040  ·  6 techniques  ·  Exfiltration, Collection, Discovery
Out1 Commodity

Gathering data and remote control.

S0594  ·  5 techniques  ·  Collection, Command and Control, Execution
RemoteUtilities Commodity

Gathering data and remote control.

S0592  ·  4 techniques  ·  Collection, Command and Control, Discovery
ConnectWise Commodity

Gathering data and running code.

S0591  ·  3 techniques  ·  Collection, Execution
No data

File hashes for MuddyWater’s own tooling

We hold none. Our corpus carries 9,780 hashes, but they come from live feeds covering current commodity campaigns — not the decade-old actor-specific backdoors in the list above. ATT&CK itself publishes no sample hashes; it is a technique knowledge base. Where a sample would have to come from a third party’s family tag rather than from this actor’s reporting, we leave the row empty instead of implying an attribution we cannot support.

04 — Coverage, honestly counted

Where the 68 techniques actually go

Of the techniques attributed to MuddyWater, 54 fold into the detection plan above, 5 describe preparation you cannot see from inside your network, and 9 are uncatalogued — we have not yet placed them. That last number is published on purpose; it is the honest size of the gap.

Execution13
Command and Control10
Stealth10
Discovery9
Credential Access6
Initial Access4
Resource Development4
Collection3
Exfiltration2
Lateral Movement2
Persistence2
Defense Impairment1
Privilege Escalation1
Reconnaissance1

05 — The chain

The order it happens in

The same techniques as above, sequenced. Useful for deciding where to spend a detection: the earlier a tactic sits, the more of the intrusion you still get to prevent.

01
Reconnaissance
1 technique
02
Resource Development
4 techniques
03
Initial Access
4 techniques
04
Execution
13 techniques
05
Persistence
2 techniques
06
Privilege Escalation
1 technique
07
Credential Access
6 techniques
08
Discovery
9 techniques
09
Lateral Movement
2 techniques
10
Collection
3 techniques
11
Command and Control
10 techniques
12
Exfiltration
2 techniques
13
Stealth
10 techniques
14
Defense Impairment
1 technique

06 — Tradecraft artefacts

Concrete strings, each with the report it came from

Pulled from primary vendor research and kept attributed. These are hunt starting points, not detections — a path an actor used once is worth a query, not a rule.

ArtefactKind First reported byDate
%programdata%\WinDir\WinDirStat.exe file path Check Point Research 2026-07-06
%programdata%\lopa.txt file path Symantec 2026-05-12
%temp%\thinking_robot_log.txt file path The Hacker News 2025-11-05
%userprofile%\Desktop\Modules\cavern\ file path Check Point Research 2026-07-06
%userprofile%\source\repos\udp_3.0 file path Unit 42 2026-03-16
%windir%\Temp file path Symantec 2026-05-12
%windir%\Temp\sam.save file path Symantec 2026-05-12
%windir%\Temp\security.save file path Symantec 2026-05-12
%windir%\Temp\system.save file path Symantec 2026-05-12
%appdata%\svchost.log file path The Hacker News 2026-04-30
HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry Symantec 2026-05-12
HKCU\Software\Classes\.wdlp registry Unit 42 2026-03-16

07 — Sourcing, graded

Who told us, and how much that is worth

NATO Admiralty grading. The letter is the source's reliability, the number the credibility of the claim. We separate primary vendor research from outlets reporting on it, because ten articles derived from one report is one report.

GradeSourceBasis
B2MITRE actor record46 references across 31 distinct research hosts
C3The Hacker News13 items — reporting on other vendors' research
B2Group-IB11 items — primary vendor research
C3Cloudsek8 items — reporting on other vendors' research
B2Check Point Research7 items — primary vendor research
B2ESET6 items — primary vendor research
C3Dark Reading4 items — reporting on other vendors' research
—Estate telemetryno data — absent, not negative

68 items · 18 outlets · 19% of reporting traces to a single outlet

08 — What we do not know

The gaps, published

Every vendor profile has these. Most omit them, which leaves you unable to tell a quiet actor from an unobserved one.

NO DATA

C2 URI fingerprints

No URI paths, headers or beacon sequences for any family we hold, and no URL indicators at all to derive them from — the indicator set is hashes, hosts and addresses.

NO DATA

Infrastructure

No domains are attributed to this actor in our holdings, so no naming convention, TLD preference or hosting pattern can be derived.

09 — Outlook

Forward judgements

Probability language is ICD 203. Likelihood and confidence are stated separately: how likely we think it is, and how good our basis is for thinking so.

Remains active
our newest reporting on this actor is from 2026-07-30, 51 days ago
ALMOST CERTAINconf HIGH
sanctioned SaaS platform as command or exfil channel continues
a tier-5–6 behaviour, which outlives the tooling that expresses it
VERY LIKELYconf MODERATE

10 — Primary sources

Every reference behind this record

46 of them. Published in full so the page can be checked rather than believed.

unit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-eascfr.orghttps://www.cfr.org/interactive/cyber-operations/muddywaterfireeye.comhttps://www.fireeye.com/blog/threat-research/2018/03/iranian-threat-group-updates-ttps-in-spear-blog.trendmicro.comhttps://blog.trendmicro.com/trendlabs-security-intelligence/campaign-possibly-connected-muddywatblog.trendmicro.comhttps://blog.trendmicro.com/trendlabs-security-intelligence/another-potential-muddywater-campaigsecurelist.comhttps://securelist.com/muddywater/88059/symantec.comhttps://www.symantec.com/blogs/threat-intelligence/seedworm-espionage-groupclearskysec.comhttps://www.clearskysec.com/wp-content/uploads/2018/11/MuddyWater-Operations-in-Lebanon-and-Omanclearskysec.comhttps://www.clearskysec.com/muddywater-targets-kurdish-groups-turkish-orgs/blog.talosintelligence.comhttps://blog.talosintelligence.com/2019/05/recent-muddywater-associated-blackwater.htmlzdnet.comhttps://www.zdnet.com/article/new-leaks-of-iranian-cyber-espionage-operations-hit-telegram-and-tattack.mitre.orghttps://attack.mitre.org/groups/G0069/secureworks.comhttp://www.secureworks.com/research/threat-profiles/cobalt-ulsterunit42.paloaltonetworks.comhttps://unit42.paloaltonetworks.com/atoms/boggyserpens/sentinelone.comhttps://www.sentinelone.com/blog/the-new-frontline-of-geopolitics-understanding-the-rise-of-stattrendmicro.comhttps://www.trendmicro.com/en_us/research/21/c/earth-vetala---muddywater-continues-to-target-orgmicrosoft.comhttps://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attackcloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-systeapt.etda.or.thhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=0d5af1f9-fa2e-4ce9-a4ce-0c6fade938e9research.checkpoint.comhttps://research.checkpoint.com/the-muddy-waters-of-apt-attacks/clearskysec.comhttps://www.clearskysec.com/muddywater2/documents.trendmicro.comhttps://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdfsymantec-enterprise-blogs.security.comhttps://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middlbleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/state-sponsored-hackers-abuse-slack-api-to-steal-clearskysec.comhttps://www.clearskysec.com/wp-content/uploads/2020/10/Operation-Quicksand.pdfzdnet.comhttps://www.zdnet.com/article/microsoft-says-iranian-hackers-are-exploiting-the-zerologon-vulnerbleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/github-hosted-malware-calculates-cobalt-strike-paanomali.comhttps://www.anomali.com/blog/probable-iranian-cyber-actors-static-kitten-conducting-cyberespionasymantec-enterprise-blogs.security.comhttps://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-campaign-teleblog.talosintelligence.comhttps://blog.talosintelligence.com/2022/01/iranian-apt-muddywater-targets-turkey.htmldeepinstinct.comhttps://www.deepinstinct.com/blog/new-muddywater-threat-old-kitten-new-trickswelivesecurity.comhttps://www.welivesecurity.com/2023/05/02/apt-groups-muddying-waters-msps/deepinstinct.comhttps://www.deepinstinct.com/blog/phonyc2-revealing-a-new-malicious-command-control-framework-bybleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/microsoft-iranian-hacking-groups-join-papercut-atdeepinstinct.comhttps://www.deepinstinct.com/blog/muddyc2go-latest-c2-framework-used-by-iranian-apt-muddywater-sdeepinstinct.comhttps://www.deepinstinct.com/blog/muddywater-en-able-spear-phishing-with-new-ttpssymantec-enterprise-blogs.security.comhttps://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africproofpoint.comhttps://www.proofpoint.com/us/blog/threat-insight/security-brief-ta450-uses-embedded-links-pdf-ablog.checkpoint.comhttps://blog.checkpoint.com/research/muddywater-threat-group-deploys-new-bugsleep-backdoor/lookout.comhttps://www.lookout.com/threat-intelligence/article/lookout-discovers-iranian-dchsy-surveillancereaqta.comhttps://reaqta.com/2017/11/muddywater-apt-targeting-middle-east/cybercom.milhttps://www.cybercom.mil/Media/News/Article/2897570/iranian-intel-cyber-suite-of-malware-uses-opcisa.govhttps://www.cisa.gov/uscert/ncas/alerts/aa22-055ablog.talosintelligence.comhttps://blog.talosintelligence.com/2022/03/iranian-supergroup-muddywater.htmlgroup-ib.comhttps://www.group-ib.com/blog/muddywater-infrastructure/pan-unit42.github.iohttps://pan-unit42.github.io/playbook_viewer/?pb=boggyserpens

Run it against your own estate

Which of these 16 behaviours do you already detect?

The library is the part we can publish. The platform runs the same detection plan against your own estate, tells you which of these behaviours you already cover, and retro-hunts the rest — on your hardware, with nothing leaving the building.

❯ ESC

THE TRACE · LOCAL INFERENCE · REASONING SHOWN STEP-BY-STEP

Try: “which of our vendors were hit by qilin” · “fortios exposure” · “what changed on our perimeter this week”