Threat actor · all actors
MuddyWaterG0069 state
🇮🇷 IR · MOIS
aka MuddyWater, Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill, COBALT ULSTER, G0069, ATK51, Boggy Serpens, MUDDYCOAST, MUDDY ION
Last updated: 2026-08-22
About this actor
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at least 2017, [MuddyWater](https://attack.mitre.org/groups/G0069) has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. [MuddyWater](https://attack.mitre.org/groups/G0069) has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, [MuddyWater](https://attack.mitre.org/groups/G0069) used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. (Citation: FalconFeeds_Iran_Mar2026)(Citation: Huntio_IranInfra_Mar2026)(Citation: Unit 42 MuddyWater Nov 2017)(Citation: Symantec MuddyWater Dec 2018)(Citation: ClearSky MuddyWater Nov 2018)(Citation: ClearSky MuddyWater June 2019)(Citation: Reaqta MuddyWater November 2017)(Citation: DHS CISA AA22-055A MuddyWater February 2022)(Citation: Talos MuddyWater Jan 2022)(Citation: NaumaanProofpoint_GlobalClickFix_April2025)(Citation: ESET_MuddyWater_Dec2025)(Citation: SymantecCarbonBlack_Seedworm_Mar2026)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantTEMP temporary cluster
Secureworkscolour-metal names
ProofpointTA threat-actor id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 94 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-22813 | 4.8 | 6.1 | 0.0093 | 2026-01-12 | see CVE |
CVE-2017-01995 | 0.0 | 0.0 | 0.0000 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.004LSA Secrets ↗T1003.005Cached Domain Credentials ↗T1016System Network Configuration Discovery ↗T1027Obfuscated Files or Information ↗T1027.003Steganography ↗T1027.004Compile After Delivery ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1041Exfiltration Over C2 Channel ↗T1047Windows Management Instrumentation ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1059.006Python ↗T1059.007JavaScript ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1090Proxy ↗T1090.002External Proxy ↗T1102Web Service ↗T1102.002Bidirectional Communication ↗T1104Multi-Stage Channels ↗T1105Ingress Tool Transfer ↗T1113Screen Capture ↗T1132Data Encoding ↗T1132.001Standard Encoding ↗T1137Office Application Startup ↗T1137.001Office Template Macros ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1204.004Malicious Copy and Paste ↗T1210Exploitation of Remote Services ↗T1218System Binary Proxy Execution ↗T1218.003CMSTP ↗T1218.005Mshta ↗T1218.011Rundll32 ↗T1219Remote Access Tools ↗T1219.002Remote Desktop Software ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1534Internal Spearphishing ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1548Abuse Elevation Control Mechanism ↗T1548.002Bypass User Account Control ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1559Inter-Process Communication ↗T1559.001Component Object Model ↗T1559.002Dynamic Data Exchange ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1571Non-Standard Port ↗T1573Encrypted Channel ↗T1573.001Symmetric Cryptography ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1583.006Web Services ↗T1588Obtain Capabilities ↗T1588.001Malware ↗T1588.002Tool ↗T1590Gather Victim Network Information ↗T1590.004Network Topology ↗T1684Social Engineering ↗T1684.001Impersonation ↗T1685Disable or Modify Tools ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 62 / 94 | 66% |
CM-6 | 56 / 94 | 60% |
CM-2 | 54 / 94 | 57% |
SI-3 | 54 / 94 | 57% |
CA-7 | 42 / 94 | 45% |
CM-7 | 41 / 94 | 44% |
AC-4 | 36 / 94 | 38% |
SC-7 | 34 / 94 | 36% |
AC-6 | 33 / 94 | 35% |
AC-3 | 31 / 94 | 33% |
AC-2 | 29 / 94 | 31% |
RA-5 | 26 / 94 | 28% |
SI-7 | 26 / 94 | 28% |
SI-2 | 24 / 94 | 26% |
SI-10 | 21 / 94 | 22% |
Co-occurring actors
- Volt Typhoon 1 shared CVEs
- Kimsuky 1 shared CVEs
- Mustang Panda 1 shared CVEs
- Gamaredon Group 1 shared CVEs
Similar actors
Similar TTPs
- BRONZE BUTLER 0.39
- Earth Lusca 0.39
- Gamaredon Group 0.36
- Mustang Panda 0.36
- Patchwork 0.35
Overlapping CVEs
- Gamaredon Group 0.50
- Mustang Panda 0.33
- Kimsuky 0.25
- Volt Typhoon 0.20
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00
Same nation-state
- HomeLand Justice 1.00
- Outer Space 1.00
- Juicy Mix 1.00
- Cleaver 1.00
- OilRig 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00