MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign
MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate (TL-2026-1530), also tracked as MuddyWater APT, is a high-severity tracked threat-actor profile, first published 2026-07-19. It is attributed to MuddyWater (Iran) with high confidence, affects Microsoft Office (Word, VBA macro engine), maps to 40 MITRE ATT&CK techniques (T1003, T1016, T1027), and is covered by 9 detection rules and 78 indicators of compromise.
Key facts for TL-2026-1530
- Threat ID
- TL-2026-1530
- Also known as
- MuddyWater APT, G0069 Campaign 2026
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_ACTOR
- First published
- 2026-07-19
- Last reviewed
- 2026-07-19
- Attribution
- MuddyWater
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- telecoms, government administration, diplomatic, education, itservices, finance, energy, insurance
- Target regions
- Middle East, 143 - Central Asia, Europe, North America, Asia, Africa
- Detection rules
- 9
- Indicators of compromise
- 78
Malware and tooling in MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate
Malware and tooling: Archer RAT, DCHSpy - S1243, GRAMDOOR, POWERSTATS, PowGoop - S1046, SHARPSTATS - S0450, Atera Agent, CrackMapExec - S0488, Empire - S0363, LaZagne - S0349, Mimikatz, N-Able
Genians reports MuddyWater, an Iranian MOIS-linked APT group tracked as G0069 (aka Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill), continuing spear-phishing campaigns using VBA macro loaders, PowerShell backdoors, and Rust-compiled payloads while abusing legitimate remote monitoring and management (RMM) tools (Syncro, Atera, Remote Utilities, ScreenConnect, SimpleHelp, N-Able, PDQ Connect, Level, Splashtop) for SYSTEM-level persistence and remote access. Campaigns span telecommunications, government/diplomatic, education, IT services, finance, and energy sectors across the Middle East, Central Asia, Europe, and North America, documented from 2019 through 2026.
How MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate works
MuddyWater (MITRE ATT&CK G0069) is a cyber-espionage group assessed as a subordinate element within Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017. The group's core tradecraft centers on spear-phishing delivery of VBA macro-laden Office documents (.doc/.docm) that trigger on Document_Open(), reconstruct hex/ASCII-encoded payloads inside UserForm objects, and spawn processes via WMI (Win32_Process) using obfuscated WScript.Shell command execution. Alongside macro loaders, MuddyWater sends HTML attachments with embedded links redirecting victims to cloud storage (OneDrive, Dropbox, Egnyte, Sync.com, Zendesk Chat/Zopim, OnHub) hosting malicious RMM installers packaged as legitimate software, and distributes encrypted RAR/ZIP archives to bypass email security scanning.
A defining and evolving TTP is the group's systematic abuse of commercial RMM platforms as first-stage payloads: since 2021 the group has cycled through ScreenConnect (ConnectWise), Syncro, SimpleHelp, Remote Utilities, Atera Agent, PDQ Connect, Level, and Splashtop, most recently exploiting Atera's free-trial signup flow (no email verification required) between October 2023 and April 2024 to stand up cloud-based C2 infrastructure without needing attacker-owned servers. These RMM tools grant SYSTEM-level remote access, file transfer, and remote shell capability while blending into normal administrative network traffic, defeating signature-based perimeter defenses. The group places a high operational priority on compromising legitimate business email accounts, which it leverages both to increase spear-phishing credibility and to maintain persistent, trusted access inside target organizations.
Through 2024-2026 the group has progressively shifted from commodity RMM abuse toward purpose-built Rust-compiled malware (RustyWater family), reflecting a deliberate operational-security and target-specificity upgrade. Rust payloads observed in November 2025 (Israeli IT provider, filename PhotoAcq.log) embed XOR-encrypted binaries in the .rdata section, enumerate 28 security products before execution, and communicate over encrypted HTTPS/TLS via SSPI contexts; PDB metadata strings such as "phoenix.pdb" have been recovered from samples.
Documented campaign activity spans an Iraqi telecom operator (March 2019, Word macro spear-phishing), a Jordanian university (April 2019, OpenXML external-template remote-template injection), Egyptian hosting/Israeli insurance/Malaysian pension-fund targets (Q4 2022-Q2 2023, HTML + OneDrive redirection), an Israeli university (April 2024, Syncro MSI installer plus encrypted RAR), Omani-impersonating diplomatic lures against foreign ministries and UN-affiliated organizations (August 2025), the November 2025 Rust-payload intrusion at an Israeli IT services provider, and a January 2026 Central Asia telecom-sector campaign using a Cybersecurity.doc dropper. MuddyWater's malware arsenal additionally includes POWERSTATS, PowGoop, SHARPSTATS, Small Sieve, STARWHALE, Mori, MuddyViper, Fooder, Tsundere Botnet, LP-Notes, and the Android surveillanceware DCHSpy, plus reliance on publicly available offensive tooling (Mimikatz, LaZagne, CrackMapExec, PowerSploit, Empire, Koadic, Rclone, Out1) for credential access and post-exploitation.
Attribution to MOIS rests on consistent Middle East-centric targeting of government and diplomatic institutions, multi-year reuse of attack infrastructure, operational tempo consistent with a state-directed unit, and sustained TTP overlap with previously identified Iran-nexus activity. No CVE/CVSS applies: initial access is achieved via phishing and legitimate-tool abuse rather than vulnerability exploitation.
MITRE ATT&CK techniques used in TL-2026-1530
Credential Access
T1003 OS Credential Dumping; T1110 Brute Force; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Discovery
T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1518 Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter
Persistence
T1053 Scheduled Task/Job; T1137 Office Application Startup; T1547 Boot or Logon Autostart Execution
Collection
T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1219 Remote Access Tools; T1571 Non-Standard Port; T1573 Encrypted Channel
Initial Access
T1199 Trusted Relationship; T1566 Phishing
stealth
T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow
lateral-movement
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
collection
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
T1590 Gather Victim Network Information
defense-impairment
Affected products and versions in MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate
- Microsoft — Office (Word, VBA macro engine)
Vulnerable versions: all versions supporting VBA macros / OpenXML remote templates - ConnectWise — ScreenConnect
Vulnerable versions: abused as legitimate installer, not a software vulnerability - Atera Networks — Atera Agent
Vulnerable versions: abused via free-trial signup abuse, not a software vulnerability - Syncro (Servably) — Syncro RMM
Vulnerable versions: abused as legitimate installer, not a software vulnerability - SimpleHelp — SimpleHelp Remote Support
Vulnerable versions: abused as legitimate installer, not a software vulnerability - Remote Utilities LLC — Remote Utilities
Vulnerable versions: abused as legitimate installer, not a software vulnerability - N-Able — N-Able RMM
Vulnerable versions: abused as legitimate installer, not a software vulnerability
Remediation for MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate
Immediate actions
- Block the identified C2 domains stratioai[.]org, nomercys.it[.]com, screenai[.]online and IPs 159.198.68.25, 159.198.66.153 at perimeter/DNS/proxy layer
- Hunt for unauthorized installations of Syncro, Atera Agent, Remote Utilities, ScreenConnect, SimpleHelp, N-Able, PDQ Connect, Level, and Splashtop across the environment
- Search for Atera Agent (or other RMM) installers configured to attacker-controlled email addresses or unfamiliar tenant/organization identifiers
- Alert on outbound connections to Egnyte, Zendesk Chat/Zopim, OnHub, and filetransfer[.]io from non-IT-managed hosts
- Quarantine and hash-match the 39 known MD5 samples across endpoints
Workarounds
- Disable OLE/DDE and remote template auto-loading in Microsoft Office where feasible
- Restrict outbound access to consumer cloud-storage and file-hosting domains from endpoints that should not require them
Longer-term hardening
- Deploy EDR with behavior-based detection for Office-process-to-script/child-process chains (WINWORD.EXE spawning wscript.exe/powershell.exe/mshta.exe)
- Restrict or block installation of unauthorized RMM software via application allowlisting; maintain an approved-RMM inventory with alerting on any RMM binary not on the list
- Enforce macro execution policies (block VBA macros from the internet, require signed macros)
- Implement conditional access and MFA on business email to reduce Business Email Compromise-enabled trusted-relationship abuse (T1199)
- Correlate free-trial RMM signups (Atera, Syncro, etc.) against organizational identity to detect fraudulent trial abuse
Timeline of MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate
- MuddyWater targets an Iraqi telecom operator via Word macro spear-phishing
- Jordanian university targeted via OpenXML external remote-template loading
- HTML + OneDrive redirection campaign begins against Egyptian hosting, Israeli insurance, and Malaysian pension-fund targets, continuing into Q2 2023
- Significant increase in Atera Agent trial-abuse installer campaigns begins, exploiting Atera's no-verification free trial signup
- Israeli university compromised via Syncro MSI installer combined with an encrypted RAR archive; Atera Agent abuse campaign tapers off around this time
- Diplomatic-impersonation campaign (Omani foreign-ministry lures) targets foreign ministries and UN-affiliated organizations
- Israeli IT services provider compromised via Rust-compiled payload (PhotoAcq.log), marking accelerated shift from commodity RMM tools to purpose-built RustyWater malware
- Central Asia telecommunications sector targeted with a Cybersecurity.doc macro dropper
- Genians Security Center publishes chronology report on ongoing MuddyWater APT attacks and RMM-tool abuse TTPs
Sources cited for MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate
- Chronology of MuddyWater APT Attacks Targeting the Middle East
- MuddyWater campaign abusing Atera Agents
- MuddyWater, Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill, Group G0069
- MuddyWater Hackers Abusing Legitimate RMM Tool to Deliver Malware
- MuddyWater Threat Actor Profile 2026: TTPs and Defenses
- The Iranian Cyber Capability 2026
- Advisory Alert: The 2026 MuddyWater Threat and How Iranian Hackers Are Bypassing Modern Security
- New MuddyWater Campaigns After Operation Swords of Iron
- Unmasking MuddyWater ConnectWise ScreenConnect Installer
- MuddyWater (G0069) Iranian APT Explained
Threats related to MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate
- Boggy Serpens (MuddyWater) AI-Enhanced Cyberespionage Campaign Deploying Nuso, LampoRAT, BlackBeard, Phoenix, and UDPGangster Malware
- Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign)
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
Detection coverage for TL-2026-1530
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1530 across Splunk SPL, Microsoft KQL and Sigma, covering 78 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.