Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ MuddyWater

🇮🇷MuddyWater

🇮🇷 MuddyWater is a tracked threat actor in the Clankerusecase corpus. Attributed to IR. Primary motivation: State. We map 26 detection use cases to this actor across 85 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2025-10-27 to 2026-03-12.

crit 2high 1med 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0069) ↗
26Use cases
4Articles
85Techniques
0IOCs

Known aliases

MuddyWaterEarth VetalaMERCURYStatic KittenMango SandstormTEMP.ZagrosSeedwormTA450MuddyKrill

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.004 · LSA SecretsT1003.005 · Cached Domain CredentialsT1016 · System Network Configuration DiscoveryT1021.002 · SMB/Windows Admin SharesT1027.003 · SteganographyT1027.004 · Compile After DeliveryT1027.010 · Command ObfuscationT1033 · System Owner/User DiscoveryT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1057 · Process DiscoveryT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1074.001 · Local Data StagingT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087 · Account DiscoveryT1087.002 · Domain AccountT1090 · ProxyT1090.002 · External ProxyT1098.005 · Device RegistrationT1102.002 · Bidirectional CommunicationT1104 · Multi-Stage ChannelsT1105 · Ingress Tool TransferT1110.003 · Password SprayingT1112 · Modify RegistryT1113 · Screen CaptureT1132.001 · Standard EncodingT1134.001 · Token Impersonation/TheftT1137.001 · Office Template MacrosT1140 · Deobfuscate/Decode Files or InformationT1195.002 · Compromise Software Supply ChainT1199 · Trusted RelationshipT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1210 · Exploitation of Remote ServicesT1218 · System Binary Proxy ExecutionT1218.003 · CMSTPT1218.005 · MshtaT1218.011 · Rundll32T1219 · Remote Access ToolsT1219.002 · Remote Desktop SoftwareT1486 · Data Encrypted for ImpactT1518 · Software DiscoveryT1518.001 · Security Software DiscoveryT1534 · Internal SpearphishingT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1552.001 · Credentials In FilesT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1556.006 · Multi-Factor AuthenticationT1559.001 · Component Object ModelT1559.002 · Dynamic Data ExchangeT1560.001 · Archive via UtilityT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1571 · Non-Standard PortT1573.001 · Symmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1583.001 · DomainsT1583.006 · Web ServicesT1588.001 · MalwareT1588.002 · ToolT1590.004 · Network TopologyT1620 · Reflective Code LoadingT1621 · Multi-Factor Authentication Request GenerationT1684.001 · ImpersonationT1685 · Disable or Modify Tools

Detection use cases (26)

MuddyWater (Mango Sandstorm / TA450) RMM-installer delivery: cloud-hosted Atera/ScreenConnect/SimpleHelp/RemoteUtilities executed after emai AI · profile SDD MuddyWater PowerShell loader chain: Office/HTA → encoded PowerShell → MuddyC2Go/PHONYC2/POWERSTATS beacon AI · profile SΣDD MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke Iran-aligned MFA push-bombing followed by new auth method registered (AA24-290A) Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal Trusted vendor binary / installer launching unusual children Internal MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Bespoke 1Password item exfiltration attempt MITRE match 1Password vault export attempted MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match

Threat-intel articles (4)

Tracked indicators

CVEs (2)

CVE-2024-42009 CVE-2025-8088