Threadlinqs IntelligenceStart free

Threat actorIranTracked since 2026-02

MuddyWater

Also known as:MuddyWater - G0069SeedwormMango SandstormStatic KittenMERCURYTA450ATK51Boggy SerpensCOBALT ULSTEREarth VetalaG0069MuddyKrill

As of 2026-08-28, MuddyWater is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 19 threats spanning threat actor, campaign, threat intel. Also known as MuddyWater - G0069, Seedworm, Mango Sandstorm, Static Kitten. ATT&CK coverage spans 179 techniques across 15 tactics in 19 of 19 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1059 (Command and Scripting Interpreter).

Tracked threats
197 critical · 11 high · 1 medium
First seen
2026-02-28
Last seen
2026-07-19
ATT&CK techniques
179across 19 of 19 threats
Related CVEs
7Referenced by its activity
Attribution
IranNation or origin
Nation: Iran · 19 tracked threat(s) · Categories: THREAT_ACTOR, CAMPAIGN, THREAT_INTEL, MALWARE, APT, VULNERABILITY, ICS_SCADA

Activity timeline

MuddyWater appears in 19 tracked threats between and ; the busiest month was 2026-03 with 9 reports.

ATT&CK techniques observed

179 techniques observed across 19 of 19 tracked threats · Stealth (formerly Defense Evasion) (28), Command and Control (18), Discovery (17), Execution (17), Resource Development (17), Credential Access (16)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 16 of 19 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 14 of 19 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 14 of 19 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 14 of 19 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 13 of 19 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 13 of 19 tracked threats
  • T1566 Phishing — Initial Accessobserved in 13 of 19 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 12 of 19 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 11 of 19 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 11 of 19 tracked threats
  • T1005 Data from Local System — Collectionobserved in 10 of 19 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 10 of 19 tracked threats
  • T1102 Web Service — Command and Controlobserved in 10 of 19 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 10 of 19 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 9 of 19 tracked threats

Tracked threats

Related CVEs

7 CVEs referenced by tracked MuddyWater activity