August 26, 2026
Updated: August 26, 2026
How an MOIS-linked espionage actor combines social engineering, scripts, legitimate remote tools, and evolving custom malware and how defenders can respond
Mohammed Khalil

MuddyWater is a useful case study in why modern threat detection cannot be reduced to finding “bad tools.” Public reporting repeatedly connects the group with phishing, PowerShell, legitimate remote-monitoring and management software, custom backdoors, and ordinary cloud or file-sharing services. Many of those technologies also support normal business operations. The defender’s task is therefore to identify unauthorized intent through context: who ran the tool, how it arrived, what it contacted, and what happened next.
MuddyWater is an Iranian cyberespionage group that U.S. authorities assess to be subordinate to Iran’s Ministry of Intelligence and Security. Active since at least 2017, it has targeted government and private organizations across the Middle East and other regions. Its reported tradecraft combines spearphishing, PowerShell, legitimate remote-monitoring and management tools, custom malware, credential access, and data collection. Defenders should not treat PowerShell or RMM software as malicious by default; they should correlate authorization, process ancestry, identity, network destinations, installation history, and follow-on behavior to distinguish administration from intrusion.
MuddyWater is the industry name for a long-running Iranian cyberespionage activity set. U.S. Cyber Command and partner agencies describe it as a subordinate element within Iran’s Ministry of Intelligence and Security, or MOIS. A 2022 joint government advisory said the actors conducted espionage and other malicious operations against government and private-sector organizations in telecommunications, defense, local government, oil and natural gas, and other sectors across several regions.
The label belongs inside a broader ecosystem of Iranian APT groups, but it should not be used as shorthand for every Iran-linked intrusion. Different organizations may share a sponsor, tools, infrastructure providers, targets, or access without being the same operating team.
MuddyWater also illustrates an important distinction in state-sponsored hacking: sophistication is not always expressed through a unique zero-day or a never-before-seen implant. A patient operator can create strategic impact by combining social engineering, valid accounts, scripts, remote access, and commercially available services.
Threat-intelligence providers name the activity they can observe. One vendor may cluster phishing infrastructure, another may track malware deployments, and another may focus on a government program. The following labels are useful cross-references, not a guarantee that every provider sees an identical set of operators and campaigns.
| Label | Source context | How to use it |
|---|---|---|
| MuddyWater | Common industry label | Use as the primary article label |
| G0069 | MITRE ATT&CK group ID | Use for ATT&CK relationships and source aggregation |
| Mango Sandstorm | Current Microsoft name | Use when reading Microsoft’s public taxonomy |
| MERCURY | Earlier Microsoft tracking name | Preserve when citing older Microsoft reporting |
| Seedworm | Symantec/Broadcom label | Use within that vendor’s campaign scope |
| Static Kitten | Industry tracking label | Treat as an associated cross-reference |
| TEMP.Zagros | Mandiant-origin label | Preserve source-specific scope and dates |
| Earth Vetala | Trend Micro label | Use within Trend Micro reporting |
| TA450 | Proofpoint email-threat cluster | Treat as overlapping MuddyWater/Mango Sandstorm activity within Proofpoint’s visibility |
The maintained MITRE ATT&CK MuddyWater profile lists these associated groups and, as of its July 31, 2026 modification, also reflects newer source material. ATT&CK is an excellent index of reported behavior, but it is not proof that every technique occurred in one campaign or remains active today.
The strongest public organizational statement comes from U.S. government reporting that identifies MuddyWater as subordinate to MOIS. That is a named government assessment. It is stronger than an inference based only on language, victim geography, or malware similarity, but it is still best described with attribution language such as “assesses,” “attributes,” or “links.”
Campaign-level attribution remains more granular. A shared code-signing certificate, RMM product, hosting provider, PowerShell pattern, or victim sector can support an assessment, but none is sufficient alone. Analysts should record which source made a claim, when it was made, what evidence was visible, and whether later research narrowed or challenged the relationship.
This discipline prevents two common errors: collapsing separate Iranian groups into one actor and attributing ordinary criminal or administrative behavior to MuddyWater merely because the same tool appeared.
Public reporting since 2017 covers government bodies and organizations in telecommunications, defense, finance, energy, oil and gas, technology, education, manufacturing, aviation, and nonprofit sectors. The Middle East has been a persistent focus, but reporting also documents activity affecting organizations in Asia, Africa, Europe, and North America.
Target lists should be treated as observed samples, not a closed universe. An organization’s practical risk depends on its strategic information, regional relationships, exposed systems, suppliers, remote-access pathways, and high-risk personnel. Sector relevance can raise priority, but it does not establish that an organization has been targeted.
| Period | Publicly reported development | Defensive significance |
|---|---|---|
| 2017–2018 | Early public reporting identified a recurring Iran-linked espionage cluster; later government reporting described broad MOIS-aligned campaigns | Establishes the group’s long operating window and regional focus |
| 2019–2021 | Reporting documented script-heavy loaders, PowerShell backdoors, obfuscation, tunneling, and regionally focused campaigns | Shows why script and process telemetry matter |
| January–February 2022 | U.S. Cyber Command publicly linked MuddyWater to MOIS; a joint advisory summarized phishing, public-vulnerability exploitation, PowerShell obfuscation, DLL side-loading, and several malware families | Provides the central public attribution and a government defensive baseline |
| 2022–2023 | Researchers documented abuse of legitimate remote-support and RMM products, including activity affecting MSP-related environments | Makes third-party access and RMM governance first-class controls |
| 2024 | Proofpoint reported PDF-link campaigns and later a ClickFix-style TA450 campaign that installed an RMM tool after socially engineered PowerShell execution | Demonstrates how user action, scripts, and legitimate remote software can form one chain |
| 2025 | ESET reported newer custom tooling, continued PowerShell and RMM reliance, and an operational overlap with a subgroup associated with OilRig | Shows evolution without abandoning familiar access patterns |
| February–March 2026 | Broadcom/Symantec reported Seedworm activity in selected U.S., Canadian, and Israeli-linked environments, with new backdoors and attempted cloud-storage exfiltration in one case | Confirms that behavior-led detection must cover custom implants, runtimes, and cloud utilities as well as RMM products |
The timeline is a selection of defensively meaningful reporting. It is not a complete incident ledger, and adjacency between rows does not prove one continuous campaign.
PowerShell is a legitimate Windows automation and administration framework. It can query systems, manage services, interact with the registry, retrieve content, and orchestrate other tools. Those same capabilities make it attractive after a foothold, especially when an operator wants to use technology already accepted in an enterprise.
This is a classic living-off-the-land problem: the binary name is a weak signal because administrators, software-management platforms, security products, and attackers may all invoke it. Context determines whether the execution is expected.
For MuddyWater, public sources have described PowerShell in several roles: script execution, payload retrieval, backdoor functionality, command-and-control logic, obfuscation, and installation of remote-management software. Defenders should treat those as historically reported capabilities, not as a promise that every current intrusion will use PowerShell.
Useful questions include:
The goal is not to alert on every PowerShell process. It is to detect improbable combinations that make legitimate-looking execution meaningful.
RMM and remote-support products help administrators maintain fleets of computers, deploy software, troubleshoot incidents, and support customers. They are not malware. Once an attacker can install or enroll an agent, however, the same product may provide persistent remote control, file transfer, command execution, and a communication channel that resembles approved IT traffic.
Proofpoint’s 2025 research described a TA450 ClickFix campaign in which a security-themed email persuaded recipients to launch PowerShell and install Level RMM. The researchers also cited prior TA450 use of Atera, PDQ Connect, ScreenConnect, and SimpleHelp. The exact product can change; the durable issue is unauthorized remote administration.
This pattern intersects with the human risk documented in DeepStrike’s phishing research. A plausible security update, trusted mailbox, PDF link, file-sharing service, or support pretext can move a user past controls without exploiting a new software vulnerability.
If the actor already has a password, repeated or manipulated authentication prompts can add another layer of social pressure. Controls designed for MFA fatigue and prompt abuse therefore complement endpoint and RMM monitoring, even though MFA fatigue is not a universal MuddyWater signature.
Public campaigns vary, but a defensively useful model has six stages.
Each stage offers a different telemetry source. Email and browser events clarify delivery; identity logs clarify account use; endpoint data clarifies process and service activity; RMM consoles clarify enrollment and operator sessions; network and cloud logs clarify destinations and transfers. Correlation is far stronger than a single alert.
The “PowerShell plus RMM” description remains useful, but it is no longer sufficient. ESET’s December 2025 MuddyWater research described continued spearphishing and RMM delivery alongside newer custom tools, credential-stealing components, loaders, reverse tunnels, and a backdoor called MuddyViper. It also reported a defined operational overlap with Lyceum, described as an OilRig subgroup, and cautiously suggested that MuddyWater may have provided initial access in that observed activity.
Broadcom/Symantec’s March 2026 Seedworm incident reporting described activity at a U.S. bank, airport, nonprofit organizations, and the Israeli operations of a U.S. software company. Researchers reported a Deno-based backdoor named Dindoor, a Python backdoor named Fakeset, and an attempted transfer to cloud storage in one environment; they did not claim a complete global victim count or confirm that the attempted exfiltration succeeded.
The defensive lesson is continuity plus adaptation. Security teams need controls for familiar scripts and RMM agents, but they must also detect unusual runtimes, new services, unexpected signed binaries, cloud-transfer utilities, credential access, and data staging. A product-denylist alone will age quickly.
ATT&CK mappings summarize techniques reported across multiple years and sources. They are useful for coverage assessment, not for identifying an actor from one event.
| ATT&CK technique | Reported behavior in the aggregated MuddyWater record | Defensive telemetry |
|---|---|---|
| T1566.001 / T1566.002 Phishing | Targeted attachments and links | Secure email gateway, mailbox audit, URL click, browser, and download logs |
| T1204.001 / T1204.002 User Execution | User interaction with links, files, or socially engineered instructions | Email-to-process correlation, browser downloads, application launches, user reports |
| T1059.001 PowerShell | Script-based execution and supporting activity | Process lineage, script-block and module logs, AMSI/EDR telemetry, account context |
| T1105 Ingress Tool Transfer | Retrieval of additional tools or remote agents | Endpoint file events, proxy, DNS, download origin, software inventory changes |
| T1219.002 Remote Desktop Software | Abuse of RMM and remote-support software | Agent installation, service creation, tenant identity, operator session, destination, file transfer |
| T1027 Obfuscated Files or Information | Obfuscated scripts or content | Script telemetry, decoding behavior, memory and endpoint analysis, unusual command patterns |
| T1053.005 Scheduled Task | Persistence through scheduled execution | Task creation events, creator identity, binary path, change ticket correlation |
| T1003 / T1555 Credential Access | Credential dumping or data from password stores in historical reporting | LSASS access alerts, browser data access, identity anomalies, privileged process telemetry |
| T1560.001 Archive via Utility | Packaging collected information | Archive creation, file volume, staging path, process ancestry |
| T1041 / T1567.002 Exfiltration | Transfer through C2 or web/cloud services | Proxy, DNS, cloud audit, DLP, transfer volume, new destination and account context |
Coverage should be tested as a chain. A medium-confidence phishing alert becomes more serious when the same user launches an unusual script, installs a new remote agent, and creates an outbound session to an unapproved tenant.
The following matrix turns “is this tool bad?” into a context-based decision.
| Signal | Trusted or expected state | Suspicious deviation | Decisive evidence | Initial response |
|---|---|---|---|---|
| Authorization | Product and version are approved; owner is documented | Tool is unknown, prohibited, or installed outside policy | Software inventory, CMDB, procurement and security policy | Identify owner; restrict or isolate if unauthorized |
| Provenance | Deployment came from an approved repository or management platform | Installer came from email, personal cloud storage, browser download, or temporary path | Download history, file origin, EDR timeline, email and proxy logs | Preserve installer and delivery evidence; block further deployment |
| Identity | Known support or automation account used expected privileges | End user, dormant account, new service account, or unusual admin token launched it | Identity provider, endpoint logon, privilege and service-account logs | Disable or constrain compromised identity; revoke sessions |
| Timing | Session aligns with a ticket, maintenance window, and user request | After-hours access, no ticket, or activity immediately after a lure | Ticketing, change management, RMM and endpoint timestamps | Contact the asset owner through a separate channel |
| Destination | Agent connects to an approved tenant, relay, or support provider | New tenant, unapproved relay, anomalous geography, or first-seen destination | RMM console, DNS, proxy, firewall, TLS and vendor records | Block or suspend unauthorized tenant and destination |
| Follow-on behavior | Bounded troubleshooting or software maintenance | Discovery, credential access, archive creation, a second RMM agent, tunneling, or bulk transfer | Cross-source timeline from endpoint, identity, network, and cloud | Escalate to incident response and scope laterally |
No single row proves MuddyWater. Several red-state signals in sequence justify containment even when attribution is unknown.
Build a complete list of approved remote products, versions, tenants, relay domains, deployment channels, owners, service accounts, and expected support windows. Block or require approval for alternatives. Alert when a second remote tool appears on a host that already has an authorized agent.
Treat MSP and vendor access as part of the same inventory. Their agents, accounts, and support workflows extend your attack surface, so they belong in continuous attack surface management, identity review, and incident exercises.
Retain process creation with parent-child relationships, command-line metadata according to policy, PowerShell script-block and module events, AMSI or equivalent inspection, file-origin data, service and task creation, and EDR events. Protect logs from alteration and synchronize time across systems.
Focus analytics on sequences: an Office application or browser produces a download; an unexpected user launches PowerShell; a new service appears; an RMM agent connects; discovery or collection follows. Tune against approved deployment patterns instead of suppressing the entire tool.
Investigate successful sign-ins after distributed failures, unusual device or geography changes, new MFA registrations, session-token anomalies, and privilege use that does not fit the user’s role. Correlate these events with downloads, remote-tool sessions, and endpoint actions.
Phishing-resistant MFA, conditional access, disabled legacy authentication, strong account recovery, and limited admin paths reduce opportunity. They do not remove the need to monitor valid sessions after compromise.
Baseline outbound destinations for remote agents, file-sharing platforms, object storage, tunnels, and synchronization tools. Alert when a rarely used transfer utility appears on a sensitive host, especially after credential access or archive creation.
Do not block a cloud provider solely because it appeared in one report. Determine which enterprise accounts, buckets, tenants, applications, and destinations are authorized, then detect deviations.
Campaign IOCs expire. Keep them as time-bounded investigative leads, but build durable hunts around delivery, process ancestry, unauthorized service creation, remote-agent enrollment, credential access, data staging, and unusual outbound transfers.
| Priority window | Actions |
|---|---|
| Immediate | Inventory approved RMM tools and tenants; restrict unapproved remote software; require strong MFA for remote access; enable relevant PowerShell and endpoint logging; preserve email, identity, endpoint, network, and RMM logs |
| Next 30 days | Centralize remote-tool deployment; remove local-admin rights where unnecessary; create detections for abnormal parent-child process chains, new services, multiple RMM agents, and unusual transfers; review MSP and vendor access; train users to report security-update and support pretexts |
| Ongoing | Patch exposed systems by risk; rehearse account and RMM compromise; validate logging coverage; rotate high-risk credentials; review new remote tools and cloud destinations; test recovery and evidence preservation |
Reducing internet-facing exposure still matters because public reporting also includes exploitation of known vulnerabilities. A mature program combines asset discovery, prioritized patching, identity security, email defenses, endpoint visibility, remote-access governance, and tested recovery.
These actions should be executed through a tested incident response plan with named authority, evidence handling, legal escalation, communications, and recovery criteria.
MuddyWater is not the same maintained activity set as OilRig/APT34. Microsoft publicly maps them to Mango Sandstorm and Hazel Sandstorm, respectively, while MITRE maintains separate group records. ESET’s report of cooperation with a subgroup associated with OilRig is evidence of an observed relationship, not proof that the groups should be merged.
MuddyWater is also distinct from Charming Kitten/APT35 and APT42 in maintained public taxonomies. Those actors may share Iranian strategic interests, phishing behavior, regional targets, or infrastructure choices, but those similarities do not establish identity.
For defenders, the actor comparison affects intelligence analysis more than first response. Contain suspicious access based on evidence; refine attribution after the environment is stable.
Tabletop exercises test decisions, but technical validation shows whether controls actually fire. A controlled red-team-versus-blue-team exercise can measure whether a realistic social-engineering-to-remote-access chain is detected and contained.
A narrower penetration testing engagement is appropriate when the immediate goal is to validate defined external, identity, application, cloud, or network attack paths. Full adversary emulation is more appropriate when the objective is to test cross-domain detection and response over time.
Any exercise should have written authorization, explicit rules of engagement, safe objectives, protected evidence, and a retest plan. It should emulate behaviors relevant to the organization without reproducing uncontrolled malware or real-world infrastructure.
MuddyWater is an Iranian cyberespionage activity set reported since at least 2017. U.S. government sources assess it to be subordinate to Iran’s Ministry of Intelligence and Security. Public reporting associates it with phishing, scripts, legitimate remote-management tools, custom malware, credential access, intelligence collection, and persistent access.
Microsoft maps MuddyWater-related activity to Mango Sandstorm, and MITRE lists Mango Sandstorm as an associated group for G0069. The names are practical cross-references, but analysts should still preserve the scope and dates of the source they are citing because vendors may observe different portions of an operation.
No, not in maintained public taxonomies. Microsoft maps OilRig/APT34 to Hazel Sandstorm and MuddyWater to Mango Sandstorm, while MITRE maintains separate profiles. Reports of cooperation or operational overlap do not make the groups identical.
PowerShell is already present in many Windows environments and supports powerful administration and automation. Public reporting describes MuddyWater using it for execution and supporting intrusion activity. Its legitimate use means defenders need process, identity, script, and network context rather than a blanket assumption that every PowerShell event is malicious.
No. They are legitimate administration and support products. Risk appears when an unauthorized person installs, enrolls, or controls them, or when their use does not match an approved tenant, operator, ticket, deployment path, or business purpose.
Government, telecommunications, defense, energy, finance, technology, aviation, manufacturing, education, nonprofit, and MSP-connected organizations appear in public reporting. Any organization with strategically valuable data, regional exposure, internet-facing systems, high-risk users, or weak remote-access governance should prioritize the underlying behaviors.
There is no single definitive signal. The strongest approach correlates phishing or download evidence, unusual PowerShell ancestry, unauthorized RMM enrollment, identity anomalies, new services or tasks, credential access, data staging, and outbound transfers. That chain can justify response even before an actor attribution is available.
MuddyWater’s enduring lesson is not that one script engine or remote product is dangerous. It is that trusted administration becomes risky when authorization, provenance, identity, destination, timing, and behavior stop lining up.
Build an approved baseline, preserve cross-domain telemetry, and respond to chains rather than isolated tool names. Then test whether the controls work under pressure. DeepStrike’s Red Teaming Services can emulate relevant behaviors under a controlled scope and turn missed detections into prioritized, retestable improvements.
Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us