All actors

MuddyWater

Also reported as TEMP.Zagros, Mango Sandstorm, MERCURY, Static Kitten, Seedworm and 16 other names. Linked to Iran by four sources.

Reports
244
Last reported
Known CVEs
267
Techniques in ATT&CK
68
Origin
Iran
ID
G0069
Merge evidence
39 alias matches

Reports per quarter

  1. 2017 Q3: 1 report
  2. 2017 Q4: 7 reports
  3. 2018 Q1: 9 reports
  4. 2018 Q2: 8 reports
  5. 2018 Q3: 1 report
  6. 2018 Q4: 12 reports
  7. 2019 Q1: 7 reports
  8. 2019 Q2: 19 reports
  9. 2019 Q3: 4 reports
  10. 2019 Q4: 8 reports
  11. 2020 Q1: 6 reports
  12. 2020 Q2: 2 reports
  13. 2020 Q3: 4 reports
  14. 2020 Q4: 7 reports
  15. 2021 Q1: 10 reports
  16. 2021 Q2: 10 reports
  17. 2021 Q3: no reports
  18. 2021 Q4: 4 reports
  19. 2022 Q1: 29 reports
  20. 2022 Q2: 8 reports
  21. 2022 Q3: 4 reports
  22. 2022 Q4: 2 reports
  23. 2023 Q1: 3 reports
  24. 2023 Q2: 6 reports
  25. 2023 Q3: 3 reports
  26. 2023 Q4: 7 reports
  27. 2024 Q1: 3 reports
  28. 2024 Q2: 3 reports
  29. 2024 Q3: 4 reports
  30. 2024 Q4: 2 reports
  31. 2025 Q1: no reports
  32. 2025 Q2: 3 reports
  33. 2025 Q3: 2 reports
  34. 2025 Q4: 5 reports
  35. 2026 Q1: 7 reports
  36. 2026 Q2: 32 reports
  37. 2026 Q3: 2 reports
Dated reports, 2017 Q3 to 2026 Q3.

Techniques seen in the last two years

Show all 127 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 267 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

Show all 244 reports Show fewer
  1. MuddyWater, Seedworm, TEMP.Zagros, Static Kitten

    date ORKL added it fromORKL

  2. POWERSTATS (Malware Family)

    date ORKL added it fromORKL

  3. PowGoop (Malware Family)

    date ORKL added it fromORKL

  4. MuddyWater eN-Able spear-phishing with new TTPs

    date in the CCS '25 data deepinstinct fromORKLCCS '25 data

  5. MuddyWaters back with DarkBit

    date in the title fromORKL

  6. New MuddyWater Threat- Old Kitten; New Tricks

    date in the title fromORKL

  7. APT trends report Q2 2020

    date in the title fromORKL

  8. eset_threat_report_t12022

    file creation date fromORKL

  9. yir-cyber-threats-report-download.pdf

    Malpedia library date fromORKL

  10. Threat Thursday- Malicious Macros Still Causing Chaos

    date in the title fromORKL

  11. MuddyWater Targets Critical Infrastructure in Asia, Europe

    date in the title fromORKL

  12. Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity

    date in the CCS '25 data mandiant fromORKLCCS '25 data

  13. Malware Analysis Report (AR22-055A) MuddyWater

    date in the title fromORKL

  14. REvil- the usage of legitimate remote admin tooling

    date in the title fromORKL

  15. MuddyWater Binder Project Part 2

    file creation date fromORKL

  16. MuddyWater- Binder Project (Part 2)

    date in the title fromORKL

  17. Muddywater- Binder Project

    date in the title fromORKL

  18. MuddyWater Binder Project Part 1

    date in the CCS '25 data ClearSky fromORKLCCS '25 data

  19. APT_trends_report_Q1_2021_Securelist

    file creation date fromORKL

  20. APT trends report Q1 2021

    date in the title fromORKL

  21. LazyScripter

    Malpedia library date Malwarebytes fromORKLCCS '25 data

  22. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  23. Reviving MuddyC3 Used by MuddyWater (IRAN) APT

    date in the title fromORKL

  24. APT trends report Q3 2020

    date in the title fromORKL

  25. APT_trends_report_Q2_2020_Securelist

    file creation date fromORKL

  26. APT trends report Q2 2020

    date in the title fromORKL

  27. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  28. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  29. Current Iran-Associated Cyber Threats

    file creation date Symantec fromORKL

  30. Iranian Threat Actors- Preliminary Analysis

    date in the title fromORKL

  31. Reviving MuddyC3 Used by MuddyWater (IRAN) APT

    date in the CCS '25 data Shells.Systems fromORKLCCS '25 data

  32. Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  33. Operation Gamework: Infrasturcture Overlaps Found Between BlueAlpha and Iranian APTs

    Malpedia library date Recorded Future fromORKLCCS '25 data

  34. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  35. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  36. MuddyWater Uses New Attack Methods in a Recent Attack Wave

    date in the title fromORKL

  37. mobile-malware-report.pdf

    file creation date fromORKL

  38. APT_trends_report_Q2_2019_Securelist

    file creation date fromORKL

  39. APT trends report Q2 2019

    date in the title fromORKL

  40. MuddyC3

    date in the CCS '25 data QiAnXin fromORKLCCS '25 data

  41. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  42. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  43. Research, News, and Perspectives

    Malpedia library date fromORKL

  44. New MuddyWater Activities Uncovered:

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  45. Malware Against the C Monoculture

    date in the title fromORKL

  46. rpt-mtrends-2019.pdf

    file creation date fromORKL

  47. The Muddy Waters of APT Attacks

    date in the CCS '25 data Check Point fromORKLCCS '25 data

  48. Report2019GlobalThreatReport

    file creation date fromORKL

  49. rpt-mtrends-2019

    file creation date fromORKL

  50. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  51. 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version

    file creation date fromORKL

  52. 2018 APT Summary Report CN version

    file creation date fromORKL

  53. 2018 Master Table

    file creation date fromORKL

  54. New PowerShell-based Backdoor Found in Turkey, Strikingly Similar to MuddyWater Tools

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  55. MuddyWater-Operations-in-Lebanon-and-Oman

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  56. MuddyWater expands operations

    date in the title fromORKL

  57. MuddyWater expands operations

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  58. Cobalt Group 2.0

    date in the title fromORKL

  59. MuddyWater_Middle_East_and_Central_Asia

    file creation date fromORKL

  60. MuddyWater's Recent Activity

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  61. A dive into MuddyWater APT targeting Middle-East - ReaQta

    date in the CCS '25 data RSA fromORKLCCS '25 data

  62. A dive into MuddyWater APT targeting Middle-East

    date in the title fromORKL

  63. A dive into MuddyWater APT targeting Middle-East

    date in the CCS '25 data Reaqta fromCCS '25 data

  64. Muddying the Water: Targeted Attacks in the Middle East

    file creation date fromORKL

  65. Muddying the Water- Targeted Attacks in the Middle East

    date in the title fromORKL

Newest first. Details opens the report in Explore.