MuddyWater
Also reported as TEMP.Zagros, Mango Sandstorm, MERCURY, Static Kitten, Seedworm and 16 other names. Linked to Iran by four sources.
Reports per quarter
Techniques seen in the last two years
- T1190 7 reports in ATT&CK
- T1566.001 5 reports in ATT&CK
- T1566.002 5 reports in ATT&CK
- T1041 4 reports in ATT&CK
- T1059.001 4 reports in ATT&CK
- T1059.003 4 reports in ATT&CK
- T1071.001 4 reports in ATT&CK
- T1082 4 reports in ATT&CK
- T1140 4 reports in ATT&CK
- T1547.001 4 reports in ATT&CK
Show all 127 techniques Show fewer
- T1573.001 4 reports in ATT&CK
- T1588.002 4 reports in ATT&CK
- T1005 3 reports reports only
- T1027 3 reports reports only
- T1059.007 3 reports in ATT&CK
- T1090.002 3 reports in ATT&CK
- T1091 3 reports reports only
- T1102.001 3 reports reports only
- T1112 3 reports reports only
- T1505.003 3 reports reports only
- T1555.003 3 reports in ATT&CK
- T1587.001 3 reports reports only
- T1659 3 reports reports only
- T1003.001 2 reports in ATT&CK
- T1036 2 reports reports only
- T1047 2 reports in ATT&CK
- T1048 2 reports reports only
- T1053 2 reports reports only
- T1059 2 reports reports only
- T1059.005 2 reports in ATT&CK
- T1074.001 2 reports in ATT&CK
- T1090 2 reports in ATT&CK
- T1095 2 reports reports only
- T1105 2 reports in ATT&CK
- T1106 2 reports reports only
- T1110.001 2 reports reports only
- T1110.003 2 reports reports only
- T1136.001 2 reports reports only
- T1189 2 reports reports only
- T1195 2 reports reports only
- T1204.001 2 reports in ATT&CK
- T1204.002 2 reports in ATT&CK
- T1219 2 reports reports only
- T1486 2 reports reports only
- T1518.001 2 reports in ATT&CK
- T1559.001 2 reports in ATT&CK
- T1560.001 2 reports in ATT&CK
- T1566.003 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports in ATT&CK
- T1583.003 2 reports reports only
- T1588.005 2 reports reports only
- T1590.002 2 reports reports only
- T1595.002 2 reports reports only
- T1595.003 2 reports reports only
- T1620 2 reports reports only
- T0835 1 report reports only
- T1001 1 report reports only
- T1003 1 report reports only
- T1003.004 1 report in ATT&CK
- T1003.005 1 report in ATT&CK
- T1016 1 report in ATT&CK
- T1021.001 1 report reports only
- T1027.003 1 report in ATT&CK
- T1027.004 1 report in ATT&CK
- T1027.007 1 report reports only
- T1027.009 1 report reports only
- T1027.010 1 report in ATT&CK
- T1027.013 1 report reports only
- T1030 1 report reports only
- T1033 1 report in ATT&CK
- T1036.004 1 report reports only
- T1036.005 1 report in ATT&CK
- T1046 1 report reports only
- T1048.003 1 report reports only
- T1049 1 report in ATT&CK
- T1053.005 1 report in ATT&CK
- T1056.001 1 report reports only
- T1056.002 1 report reports only
- T1057 1 report in ATT&CK
- T1059.006 1 report in ATT&CK
- T1070 1 report reports only
- T1070.004 1 report reports only
- T1070.009 1 report reports only
- T1071 1 report reports only
- T1083 1 report in ATT&CK
- T1087.002 1 report in ATT&CK
- T1098 1 report reports only
- T1102.002 1 report in ATT&CK
- T1104 1 report in ATT&CK
- T1113 1 report in ATT&CK
- T1114 1 report reports only
- T1115 1 report reports only
- T1125 1 report reports only
- T1129 1 report reports only
- T1132.001 1 report in ATT&CK
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1134.002 1 report reports only
- T1137.001 1 report in ATT&CK
- T1185 1 report reports only
- T1202 1 report reports only
- T1203 1 report in ATT&CK
- T1204.004 1 report in ATT&CK
- T1210 1 report in ATT&CK
- T1212 1 report reports only
- T1218.003 1 report in ATT&CK
- T1218.005 1 report in ATT&CK
- T1218.011 1 report in ATT&CK
- T1485 1 report reports only
- T1490 1 report reports only
- T1497.003 1 report reports only
- T1518 1 report in ATT&CK
- T1543.003 1 report reports only
- T1548.002 1 report in ATT&CK
- T1552.001 1 report in ATT&CK
- T1555 1 report in ATT&CK
- T1557 1 report reports only
- T1559 1 report reports only
- T1559.002 1 report in ATT&CK
- T1574.001 1 report in ATT&CK
- T1583 1 report reports only
- T1583.006 1 report in ATT&CK
- T1591 1 report reports only
- T1608 1 report reports only
- T1614 1 report reports only
- T1622 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-5633
- CVE-2008-3431 KEV
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-1592
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
Show all 267 CVEs Show fewer
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-7331 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2015-1635 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-2051 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-01995
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-17215
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-7269 KEV
- CVE-2017-7921 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-15454
- CVE-2018-1579
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-4990 KEV
- CVE-2018-5002 KEV
- CVE-2018-6055
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8242
- CVE-2018-8373 KEV
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8414 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-35730 KEV
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-21974
- CVE-2021-26084 KEV ransomware
- CVE-2021-26334
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-34523 KEV ransomware
- CVE-2021-3970
- CVE-2021-3971
- CVE-2021-3972
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0847 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-34362 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2023-6895
- CVE-2024-11182 KEV
- CVE-2024-1709 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21893 KEV ransomware
- CVE-2024-23113 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-49039 KEV ransomware
- CVE-2024-5559
- CVE-2024-55591 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
- CVE-2024-9680 KEV ransomware
- CVE-2025-12819
- CVE-2025-34291 KEV
- CVE-2025-52691 KEV ransomware
- CVE-2025-54068 KEV
- CVE-2025-55182 KEV ransomware
- CVE-2025-5777 KEV ransomware
- CVE-2025-68613 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2025-9316
- CVE-2026-1281 KEV
- CVE-2026-1731 KEV ransomware
- CVE-2026-22813
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
Show all 244 reports Show fewer
-
Subgroup: [Unnamed group USA] - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Subgroup: [Unnamed group USA] - Threat Group Cards: A Threat Actor Encyclopedia
-
MuddyWater, Seedworm, TEMP.Zagros, Static Kitten
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MuddyWater, Seedworm, TEMP.Zagros, Static Kitten
-
New PowerShell-based Backdoor, MuddyWater Similarities
The original link failed its last check. Original publisher Detailsfor New PowerShell-based Backdoor, MuddyWater Similarities
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor POWERSTATS (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
New BugSleep Backdoor Deployed in Recent MuddyWater Campaigns - Check Point Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New BugSleep Backdoor Deployed in Recent MuddyWater Campaigns - Check Point Research
-
Seedworm_ Iranian Hackers Target Telecoms Orgs in North and East Africa _ Symantec Enterprise Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Seedworm_ Iranian Hackers Target Telecoms Orgs in North and East Africa _ Symantec Enterprise Blogs
-
Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa
-
MuddyWater eN-Able spear-phishing with new TTPs
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor MuddyWater eN-Able spear-phishing with new TTPs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWaters back with DarkBit
-
MERCURY and DEV-1084- Destructive attack on hybrid environment
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MERCURY and DEV-1084- Destructive attack on hybrid environment
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Do You Like Dem Eggs- I like Mine Scrambled, Really Scrambled - A Look at Recent more_eggs Samples
-
New MuddyWater Threat- Old Kitten; New Tricks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New MuddyWater Threat- Old Kitten; New Tricks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
MuddyWater’s “light” first-stager targetting Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater’s “light” first-stager targetting Middle East
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12022
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of an Iranian APTs E400 PowGoop Variant Reveals Dozens of Control Servers Dating Back to 202
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
Threat Thursday- Malicious Macros Still Causing Chaos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday- Malicious Macros Still Causing Chaos
-
Iranian APT- New Methods to Target Turkey, Arabian Peninsula
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian APT- New Methods to Target Turkey, Arabian Peninsula
-
Iranian Hackers Targeting Turkey and Arabian Peninsula in New Malware Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Hackers Targeting Turkey and Arabian Peninsula in New Malware Campaign
-
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
-
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian linked conglomerate MuddyWater comprised of regionally focused subgroups
-
MuddyWater targets Middle Eastern and Asian countries in phishing attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater targets Middle Eastern and Asian countries in phishing attacks
-
MuddyWater Targets Critical Infrastructure in Asia, Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater Targets Critical Infrastructure in Asia, Europe
-
Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity
-
Malware Analysis Report (AR22-055A) MuddyWater
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Analysis Report (AR22-055A) MuddyWater
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-055A) Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks
-
Left On Read- Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Left On Read- Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity
-
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco Talos Intelligence Group - Comprehensive Threat Intelligence_ Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables
-
Wading Through Muddy Waters - Recent Activity of an Iranian State-Sponsored Threat Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Wading Through Muddy Waters - Recent Activity of an Iranian State-Sponsored Threat Actor
-
Iranian intel cyber suite of malware uses open source tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian intel cyber suite of malware uses open source tools
-
Espionage Campaign Targets Telecoms Organizations across Middle East and Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Espionage Campaign Targets Telecoms Organizations across Middle East and Asia
-
WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019
-
REvil- the usage of legitimate remote admin tooling
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor REvil- the usage of legitimate remote admin tooling
-
The blurry boundaries between nation-state actors and the cybercrime underground
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The blurry boundaries between nation-state actors and the cybercrime underground
-
MuddyWater Binder Project Part 2
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater Binder Project Part 2
-
MuddyWater- Binder Project (Part 2)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater- Binder Project (Part 2)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Muddywater- Binder Project
-
MuddyWater Binder Project Part 1
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater Binder Project Part 1
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor LazyScripter
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies
-
Reviving MuddyC3 Used by MuddyWater (IRAN) APT
The original link failed its last check. Original publisher Detailsfor Reviving MuddyC3 Used by MuddyWater (IRAN) APT
-
Reviving MuddyC3 Used by MuddyWater (IRAN) APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reviving MuddyC3 Used by MuddyWater (IRAN) APT
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
Seedworm- Iran-Linked Group Continues to Target Organizations in the Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Seedworm- Iran-Linked Group Continues to Target Organizations in the Middle East
-
'MuddyWater' spies suspected in attacks against Middle East governments, telecoms
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 'MuddyWater' spies suspected in attacks against Middle East governments, telecoms
-
2020.10.15_Operation_Quicksand_MuddyWater’s_Offensive_Attack_Against_Israeli
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.10.15_Operation_Quicksand_MuddyWater’s_Offensive_Attack_Against_Israeli
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
Business as Usual For Iranian Operations Despite Increased Tensions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Business as Usual For Iranian Operations Despite Increased Tensions
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Current Iran-Associated Cyber Threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Current Iran-Associated Cyber Threats
-
Iranian Threat Actors- Preliminary Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Actors- Preliminary Analysis
-
Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Cyber Response to Death of IRGC Head Would Likely Use Reported TTPs and Previous Access
-
Reviving MuddyC3 Used by MuddyWater (IRAN) APT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Reviving MuddyC3 Used by MuddyWater (IRAN) APT
-
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
-
Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
MuddyWater Uses New Attack Methods in a Recent Attack Wave
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater Uses New Attack Methods in a Recent Attack Wave
-
The original link failed its last check. Original publisher Detailsfor mobile-malware-report.pdf
-
APT_trends_report_Q2_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2019_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2019
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Actor Amasses Large Cyber Operations Infrastructure Network to Target Saudi Organizations
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyC3
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
New MuddyWater Activities Uncovered:
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New MuddyWater Activities Uncovered:
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools - TrendLabs Security Intelligence Blog
-
MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools
-
Recent MuddyWater-associated BlackWater campaign shows signs of new anti-detection techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Recent MuddyWater-associated BlackWater campaign shows signs of new anti-detection techniques
-
Malware Against the C Monoculture
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Against the C Monoculture
-
New leaks of Iranian cyber-espionage operations hit Telegram and the Dark Web
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New leaks of Iranian cyber-espionage operations hit Telegram and the Dark Web
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
The Muddy Waters of APT Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Muddy Waters of APT Attacks
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
-
2018 APT Summary Report CN version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 APT Summary Report CN version
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
POWERSING - From LNK Files To Janicab Through YouTube & Twitter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor POWERSING - From LNK Files To Janicab Through YouTube & Twitter
-
Seedworm- Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Seedworm- Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms
-
New PowerShell-based Backdoor Found in Turkey, Strikingly Similar to MuddyWater Tools
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New PowerShell-based Backdoor Found in Turkey, Strikingly Similar to MuddyWater Tools
-
MuddyWater-Operations-in-Lebanon-and-Oman
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater-Operations-in-Lebanon-and-Oman
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater expands operations
-
The link to CyberMonitor archive on GitHub failed its last check. CyberMonitor archive on GitHub Detailsfor MuddyWater expands operations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Group 2.0
-
Accenture-Cyber-Threatscape-Report-2018.pdf
The original link failed its last check. Original publisher Detailsfor Accenture-Cyber-Threatscape-Report-2018.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor - TrendLabs Security Intelligence Blog
-
Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor
-
Potential MuddyWater Campaign uses PRB-Backdoor
The original link failed its last check. Original publisher Detailsfor Potential MuddyWater Campaign uses PRB-Backdoor
-
PRB-Backdoor - A Fully Loaded PowerShell Backdoor with Evil Intentions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PRB-Backdoor - A Fully Loaded PowerShell Backdoor with Evil Intentions
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign « Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign | FireEye Inc
-
Falling on MuddyWater – Where security meets innovation
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Falling on MuddyWater – Where security meets innovation
-
MuddyWater_Middle_East_and_Central_Asia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater_Middle_East_and_Central_Asia
-
Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign
-
Potential MuddyWater Campaign Seen in the Middle East
The original link failed its last check. Original publisher Detailsfor Potential MuddyWater Campaign Seen in the Middle East
-
Campaign Possibly Connected to “MuddyWater” Surfaces in the Middle East and Central Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Campaign Possibly Connected to “MuddyWater” Surfaces in the Middle East and Central Asia
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater's Recent Activity
-
A dive into MuddyWater APT targeting Middle-East - ReaQta
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A dive into MuddyWater APT targeting Middle-East - ReaQta
-
A dive into MuddyWater APT targeting Middle-East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A dive into MuddyWater APT targeting Middle-East
-
A dive into MuddyWater APT targeting Middle-East
The original link failed its last check. Detailsfor A dive into MuddyWater APT targeting Middle-East
-
Muddying the Water: Targeted Attacks in the Middle East
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Muddying the Water: Targeted Attacks in the Middle East
-
Muddying the Water- Targeted Attacks in the Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Muddying the Water- Targeted Attacks in the Middle East
Newest first. Details opens the report in Explore.