Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0069
MITRE ATT&CK Group

MuddyWater (G0069)

Earth VetalaMERCURYStatic KittenSeedwormTEMP.ZagrosMango SandstormTA450MuddyKrill
ShareXLinkedInRedditHN

[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at least 2017, [MuddyWater](https://attack.mitre.org/groups/G0069) has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. [MuddyWater](https://attack.mitre.org/groups/G0069) has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, [MuddyWater](https://attack.mitre.org/groups/G0069) used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. (Citation: FalconFeeds_Iran_Mar2026)(Citation: Huntio_IranInfra_Mar2026)(Citation: Unit 42 MuddyWater Nov 2017)(Citation: Symantec MuddyWater Dec 2018)(Citation: ClearSky MuddyWater Nov 2018)(Citation: ClearSky MuddyWater June 2019)(Citation: Reaqta MuddyWater November 2017)(Citation: DHS CISA AA22-055A MuddyWater February 2022)(Citation: Talos MuddyWater Jan 2022)(Citation: NaumaanProofpoint_GlobalClickFix_April2025)(Citation: ESET_MuddyWater_Dec2025)(Citation: SymantecCarbonBlack_Seedworm_Mar2026)

▪Techniques used (68)

T1566.002Spearphishing LinkT1137.001Office Template MacrosT1574.001DLLT1588.002ToolT1218.005MshtaT1204.004Malicious Copy and PasteT1047Windows Management InstrumentationT1534Internal SpearphishingT1003.004LSA SecretsT1566.001Spearphishing AttachmentT1583.001DomainsT1590.004Network TopologyT1559.001Component Object ModelT1571Non-Standard PortT1059.003Windows Command ShellT1588.001MalwareT1218.003CMSTPT1036.005Match Legitimate Resource Name or LocationT1087.002Domain AccountT1059.007JavaScriptT1583.006Web ServicesT1059.005Visual BasicT1016System Network Configuration DiscoveryT1547.001Registry Run Keys / Startup FolderT1140Deobfuscate/Decode Files or InformationT1559.002Dynamic Data ExchangeT1027.010Command ObfuscationT1027.004Compile After DeliveryT1518.001Security Software DiscoveryT1074.001Local Data StagingT1113Screen CaptureT1071.001Web ProtocolsT1685Disable or Modify ToolsT1518Software DiscoveryT1083File and Directory DiscoveryT1548.002Bypass User Account ControlT1105Ingress Tool TransferT1573.001Symmetric CryptographyT1567.002Exfiltration to Cloud StorageT1555.003Credentials from Web BrowsersT1566PhishingT1560.001Archive via UtilityT1684.001ImpersonationT1059.006PythonT1049System Network Connections DiscoveryT1082System Information DiscoveryT1555Credentials from Password StoresT1057Process DiscoveryT1132.001Standard EncodingT1104Multi-Stage ChannelsT1090ProxyT1204.001Malicious LinkT1027.003SteganographyT1003.001LSASS MemoryT1053.005Scheduled TaskT1090.002External ProxyT1204.002Malicious FileT1033System Owner/User DiscoveryT1219.002Remote Desktop SoftwareT1041Exfiltration Over C2 ChannelT1059.001PowerShellT1102.002Bidirectional CommunicationT1218.011Rundll32T1552.001Credentials In FilesT1190Exploit Public-Facing ApplicationT1210Exploitation of Remote ServicesT1203Exploitation for Client ExecutionT1003.005Cached Domain Credentials

▪Software used (22)

S9032MuddyVipermalwareS1037STARWHALEmalwareS9036LP-NotesmalwareS0223POWERSTATSmalwareS1040RclonetoolS0594Out1toolS9034Tsundere BotnetmalwareS0194PowerSploittoolS1035Small SievemalwareS9033FoodermalwareS1047MorimalwareS0002MimikatztoolS0349LaZagnetoolS1046PowGoopmalwareS0488CrackMapExectoolS0591ConnectWisetoolS0450SHARPSTATSmalwareS0363EmpiretoolS9037RustyWatermalwareS0592RemoteUtilitiestoolS0250KoadictoolS1243DCHSpymalware
G0069on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.