68
Techniques
21
Toolsets
3
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.

View MITRE record ↗

Techniques by Tactic (68)
Toolsets (21)
🐛
Fooder S9033
Malware · Windows
🐛
LP-Notes S9036
Malware · Windows
🐛
Mori S1047
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Windows
🐛
PowGoop S1046
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Windows
🐛
STARWHALE S1037
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Linux, macOS, Windows
🔧
Tool · Windows
🔧
Tool · Windows
🔧
Empire S0363
Tool · Linux, macOS, Windows
🔧
Koadic S0250
Tool · Windows
🔧
LaZagne S0349
Tool · Linux, macOS, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
Out1 S0594
Tool · Windows
🔧
Tool · Windows
🔧
Rclone S1040
Tool · Linux, Windows, macOS
🔧
Tool · Windows
CVEs Referenced (3 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
CVE-2017-0176View full details on NVD
References & Reports (19)
↑