← Threat Actors / Iran / MuddyWater
DOSSIER // MUDDYWATER

MuddyWater

▲ High Threat Iran
Primary Aliases: Mango Sandstorm Static Kitten ATK51 Boggy Serpens
Sponsor / State Affiliation Iran (Islamic Republic of)
Primary Motivation Espionage
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.

🎯 Target Sectors & Focus

Government Telecom Defense Energy Middle East / Europe

🛡️ MITRE ATT&CK® Attack Lifecycle (68 TTPs)

📥 Download Navigator JSON
Persistence & Privilege Escalation 1
Copied to clipboard

LINK COPIED TO CLIPBOARD