MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign — Threadlinqs Intelligence
As of 2026-07-19, MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign is a high-severity threat actor threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 78 indicators of compromise.
Threat ID: TL-2026-1530 · Severity: HIGH · Status: ACTIVE · Category: THREAT_ACTOR
Attribution: MuddyWater · Iran · ESPIONAGE
Genians reports MuddyWater, an Iranian MOIS-linked APT group tracked as G0069 (aka Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill), continuing
MuddyWater (MITRE ATT&CK G0069) is a cyber-espionage group assessed as a subordinate element within Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017. The group's core tradecraft centers on spear-phishing delivery of VBA macro-laden Office documents (.doc/.docm) that trigger on Document_Open(), reconstruct hex/ASCII-encoded payloads inside UserForm objects, and spawn processes via WMI (Win32_Process) using obfuscated WScript.Shell command execution. Alongside macro loaders, MuddyWater sends HTML attachments with embedded links redirecting victims to cloud storage (OneDrive, Dropbox, Egnyte, Sync.com, Zendesk Chat/Zopim, OnHub) hosting malicious RMM installers packaged as legitimate software, and distributes encrypted RAR/ZIP archives to bypass email security scanning.
A defining and evolving TTP is the group's systematic abuse of commercial RMM platforms as first-stage payloads: since 2021 the group has cycled through ScreenConnect (ConnectWise), Syncro, SimpleHelp, Remote Utilities, Atera Agent, PDQ Connect, Level, and Splashtop, most recently exploiting Atera's free-trial signup flow (no email verification required) between October 2023 and April 2024 to stand up cloud-based C2 infrastructure without needing attacker-owned servers. These RMM tools grant SYSTEM-level remote access, file transfer, and remote shell capability while blending into normal administrative network traffic, defeating signature-based perimeter defenses. The group places a high operational priority on compromising legitimate business email accounts, which it leverages both to increase spear-phishing credibility and to maintain persistent, trusted access inside target organizations.
Through 2024-2026 the group has progressively shifted from commodity RMM abuse toward purpose-built Rust-compiled malware (RustyWater family), reflecting a deliberate operational-security and target-specificity upgrade. Rust payloads observed in November 2025 (Israeli IT provider, filename PhotoAcq.log) embed XOR-encrypted binaries in the .rdata section, enumerate 28 security products before execution, and communicate over encrypted HTTPS/TLS via SSPI contexts; PDB metadata strings such as "phoenix.pdb" have been recovered from samples.
Documented campaign activity spans an Iraqi telecom operator (March 2019, Word macro spear-phishing), a Jordanian university (April 2019, OpenXML external-template remote-template injection), Egyptian hosting/Israeli insurance/Malaysian pension-fund targets (Q4 2022-Q2 2023, HTML + OneDrive redirection), an Israeli university (April 2024, Syncro MSI installer plus encrypted RAR), Omani-impersonating diplomatic lures against foreign ministries and UN-affiliated organizations (August 2025), the November 2025 Rust-payload intrusion at an Israeli IT services provider, and a January 2026 Central Asia telecom-sector campaign using a Cybersecurity.doc dropper. MuddyWater's malware arsenal additionally includes POWERSTATS, PowGoop, SHARPSTATS, Small Sieve, STARWHALE, Mori, MuddyViper, Fooder, Tsundere Botnet, LP-Notes, and the Android surveillanceware DCHSpy, plus reliance on publicly available offensive tooling (Mimikatz, LaZagne, CrackMapExec, PowerSploit, Empire, Koadic, Rclone, Out1) for credential access and post-exploitation.
Attribution to MOIS rests on consistent Middle East-centric targeting of government and diplomatic institutions, multi-year reuse of attack infrastructure, operational tempo consistent with a state-directed unit, and sustained TTP overlap with previously identified Iran-nexus activity. No CVE/CVSS applies: initial access is achieved via phishing and legitimate-tool abuse rather than vulnerability exploitation.
Target sectors: telecoms, government administration, diplomatic, education, itservices, finance, energy, insurance
Target regions: Middle East, 143 - Central Asia, Europe, North America, Asia, Africa
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 78 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_ACTOR, HIGH, threat intelligence, cybersecurity, T1590, T1583, T1583, T1588, T1588, T1566, T1566, T1566, T1534, T1199