Activity timeline
MuddyWater appears in 19 tracked threats between and ; the busiest month was 2026-03 with 9 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 16 of 19 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 14 of 19 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 14 of 19 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 14 of 19 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 13 of 19 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 13 of 19 tracked threats
- T1566 Phishing — Initial Accessobserved in 13 of 19 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistenceobserved in 12 of 19 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 11 of 19 tracked threats
- T1555 Credentials from Password Stores — Credential Accessobserved in 11 of 19 tracked threats
- T1005 Data from Local System — Collectionobserved in 10 of 19 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 10 of 19 tracked threats
- T1102 Web Service — Command and Controlobserved in 10 of 19 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 10 of 19 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 9 of 19 tracked threats
Tracked threats
- MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaignHIGH
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- ClickFix / KongTuke Clipboard-Hijacking Social-Engineering Technique (MITRE T1204.004) — Fake-CAPTCHA Lures Delivering Infostealers, RATs, and RansomwareHIGH
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion TechniquesHIGH
- Deno-Based Modular RAT & Internal Proxy Delivered via Mailbombing + Microsoft Teams Vishing ("DenoJSEnv")HIGH
- Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software CompanyCRITICAL
- DinDoor Deno-Based RAT — Fake AI/Audio Software on GitHub & SourceForge (ChatGPT/Claude/AutoTune/Kontakt) via Compromised YouTube ChannelsHIGH
- Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and SentinelOne Binaries, ChromElevator Browser Theft, Node.js/PowerShell Implant ChainHIGH
- MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering, DWAgent Persistence, Game.exe RAT Trojanizing Microsoft WebView2APISample (Operation Olalampo Link)HIGH
- Laravel Livewire Unauthenticated RCE via Synthesizer Smuggling — MuddyWater Active Exploitation (CVE-2025-54068)CRITICAL
- Iran Conflict Cyber Operations: MuddyWater (Seedworm) Deploys New Dindoor and Fakeset Backdoors Against US Banks, Airports, Non-Profits, and Defense/Aerospace Software Providers (Feb-Mar 2026)HIGH
- Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign)HIGH
- Boggy Serpens (MuddyWater) AI-Enhanced Cyberespionage Campaign Deploying Nuso, LampoRAT, BlackBeard, Phoenix, and UDPGangster MalwareHIGH
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater CampaignCRITICAL
- Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical InfrastructureCRITICAL
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)CRITICAL
- Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset BackdoorsCRITICAL
- CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware Suite with Telegram Bot C2CRITICAL
- MuddyWater Operation Olalampo — Iran MOIS-Nexus APT Deploys New Malware Variants with Telegram Bot C2 Targeting Middle Eastern Governments and Critical InfrastructureHIGH