MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign

MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate (TL-2026-1530), also tracked as MuddyWater APT, is a high-severity tracked threat-actor profile, first published 2026-07-19. It is attributed to MuddyWater (Iran) with high confidence, affects Microsoft Office (Word, VBA macro engine), maps to 40 MITRE ATT&CK techniques (T1003, T1016, T1027), and is covered by 9 detection rules and 78 indicators of compromise.

Key facts for TL-2026-1530

Threat ID
TL-2026-1530
Also known as
MuddyWater APT, G0069 Campaign 2026
Severity
HIGH
Status
ACTIVE
Category
THREAT_ACTOR
First published
2026-07-19
Last reviewed
2026-07-19
Attribution
MuddyWater
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
telecoms, government administration, diplomatic, education, itservices, finance, energy, insurance
Target regions
Middle East, 143 - Central Asia, Europe, North America, Asia, Africa
Detection rules
9
Indicators of compromise
78

Malware and tooling in MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate

Malware and tooling: Archer RAT, DCHSpy - S1243, GRAMDOOR, POWERSTATS, PowGoop - S1046, SHARPSTATS - S0450, Atera Agent, CrackMapExec - S0488, Empire - S0363, LaZagne - S0349, Mimikatz, N-Able

Genians reports MuddyWater, an Iranian MOIS-linked APT group tracked as G0069 (aka Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill), continuing spear-phishing campaigns using VBA macro loaders, PowerShell backdoors, and Rust-compiled payloads while abusing legitimate remote monitoring and management (RMM) tools (Syncro, Atera, Remote Utilities, ScreenConnect, SimpleHelp, N-Able, PDQ Connect, Level, Splashtop) for SYSTEM-level persistence and remote access. Campaigns span telecommunications, government/diplomatic, education, IT services, finance, and energy sectors across the Middle East, Central Asia, Europe, and North America, documented from 2019 through 2026.

How MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate works

MuddyWater (MITRE ATT&CK G0069) is a cyber-espionage group assessed as a subordinate element within Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017. The group's core tradecraft centers on spear-phishing delivery of VBA macro-laden Office documents (.doc/.docm) that trigger on Document_Open(), reconstruct hex/ASCII-encoded payloads inside UserForm objects, and spawn processes via WMI (Win32_Process) using obfuscated WScript.Shell command execution. Alongside macro loaders, MuddyWater sends HTML attachments with embedded links redirecting victims to cloud storage (OneDrive, Dropbox, Egnyte, Sync.com, Zendesk Chat/Zopim, OnHub) hosting malicious RMM installers packaged as legitimate software, and distributes encrypted RAR/ZIP archives to bypass email security scanning.

A defining and evolving TTP is the group's systematic abuse of commercial RMM platforms as first-stage payloads: since 2021 the group has cycled through ScreenConnect (ConnectWise), Syncro, SimpleHelp, Remote Utilities, Atera Agent, PDQ Connect, Level, and Splashtop, most recently exploiting Atera's free-trial signup flow (no email verification required) between October 2023 and April 2024 to stand up cloud-based C2 infrastructure without needing attacker-owned servers. These RMM tools grant SYSTEM-level remote access, file transfer, and remote shell capability while blending into normal administrative network traffic, defeating signature-based perimeter defenses. The group places a high operational priority on compromising legitimate business email accounts, which it leverages both to increase spear-phishing credibility and to maintain persistent, trusted access inside target organizations.

Through 2024-2026 the group has progressively shifted from commodity RMM abuse toward purpose-built Rust-compiled malware (RustyWater family), reflecting a deliberate operational-security and target-specificity upgrade. Rust payloads observed in November 2025 (Israeli IT provider, filename PhotoAcq.log) embed XOR-encrypted binaries in the .rdata section, enumerate 28 security products before execution, and communicate over encrypted HTTPS/TLS via SSPI contexts; PDB metadata strings such as "phoenix.pdb" have been recovered from samples.

Documented campaign activity spans an Iraqi telecom operator (March 2019, Word macro spear-phishing), a Jordanian university (April 2019, OpenXML external-template remote-template injection), Egyptian hosting/Israeli insurance/Malaysian pension-fund targets (Q4 2022-Q2 2023, HTML + OneDrive redirection), an Israeli university (April 2024, Syncro MSI installer plus encrypted RAR), Omani-impersonating diplomatic lures against foreign ministries and UN-affiliated organizations (August 2025), the November 2025 Rust-payload intrusion at an Israeli IT services provider, and a January 2026 Central Asia telecom-sector campaign using a Cybersecurity.doc dropper. MuddyWater's malware arsenal additionally includes POWERSTATS, PowGoop, SHARPSTATS, Small Sieve, STARWHALE, Mori, MuddyViper, Fooder, Tsundere Botnet, LP-Notes, and the Android surveillanceware DCHSpy, plus reliance on publicly available offensive tooling (Mimikatz, LaZagne, CrackMapExec, PowerSploit, Empire, Koadic, Rclone, Out1) for credential access and post-exploitation.

Attribution to MOIS rests on consistent Middle East-centric targeting of government and diplomatic institutions, multi-year reuse of attack infrastructure, operational tempo consistent with a state-directed unit, and sustained TTP overlap with previously identified Iran-nexus activity. No CVE/CVSS applies: initial access is achieved via phishing and legitimate-tool abuse rather than vulnerability exploitation.

MITRE ATT&CK techniques used in TL-2026-1530

Credential Access

T1003 OS Credential Dumping; T1110 Brute Force; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter

Persistence

T1053 Scheduled Task/Job; T1137 Office Application Startup; T1547 Boot or Logon Autostart Execution

Collection

T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1219 Remote Access Tools; T1571 Non-Standard Port; T1573 Encrypted Channel

Initial Access

T1199 Trusted Relationship; T1566 Phishing

stealth

T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow

lateral-movement

T1534 Internal Spearphishing

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

collection

T1560 Archive Collected Data

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate

  • Microsoft — Office (Word, VBA macro engine)
    Vulnerable versions: all versions supporting VBA macros / OpenXML remote templates
  • ConnectWise — ScreenConnect
    Vulnerable versions: abused as legitimate installer, not a software vulnerability
  • Atera Networks — Atera Agent
    Vulnerable versions: abused via free-trial signup abuse, not a software vulnerability
  • Syncro (Servably) — Syncro RMM
    Vulnerable versions: abused as legitimate installer, not a software vulnerability
  • SimpleHelp — SimpleHelp Remote Support
    Vulnerable versions: abused as legitimate installer, not a software vulnerability
  • Remote Utilities LLC — Remote Utilities
    Vulnerable versions: abused as legitimate installer, not a software vulnerability
  • N-Able — N-Able RMM
    Vulnerable versions: abused as legitimate installer, not a software vulnerability

Remediation for MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate

Immediate actions

  • Block the identified C2 domains stratioai[.]org, nomercys.it[.]com, screenai[.]online and IPs 159.198.68.25, 159.198.66.153 at perimeter/DNS/proxy layer
  • Hunt for unauthorized installations of Syncro, Atera Agent, Remote Utilities, ScreenConnect, SimpleHelp, N-Able, PDQ Connect, Level, and Splashtop across the environment
  • Search for Atera Agent (or other RMM) installers configured to attacker-controlled email addresses or unfamiliar tenant/organization identifiers
  • Alert on outbound connections to Egnyte, Zendesk Chat/Zopim, OnHub, and filetransfer[.]io from non-IT-managed hosts
  • Quarantine and hash-match the 39 known MD5 samples across endpoints

Workarounds

  • Disable OLE/DDE and remote template auto-loading in Microsoft Office where feasible
  • Restrict outbound access to consumer cloud-storage and file-hosting domains from endpoints that should not require them

Longer-term hardening

  • Deploy EDR with behavior-based detection for Office-process-to-script/child-process chains (WINWORD.EXE spawning wscript.exe/powershell.exe/mshta.exe)
  • Restrict or block installation of unauthorized RMM software via application allowlisting; maintain an approved-RMM inventory with alerting on any RMM binary not on the list
  • Enforce macro execution policies (block VBA macros from the internet, require signed macros)
  • Implement conditional access and MFA on business email to reduce Business Email Compromise-enabled trusted-relationship abuse (T1199)
  • Correlate free-trial RMM signups (Atera, Syncro, etc.) against organizational identity to detect fraudulent trial abuse

Timeline of MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate

  • MuddyWater targets an Iraqi telecom operator via Word macro spear-phishing
  • Jordanian university targeted via OpenXML external remote-template loading
  • HTML + OneDrive redirection campaign begins against Egyptian hosting, Israeli insurance, and Malaysian pension-fund targets, continuing into Q2 2023
  • Significant increase in Atera Agent trial-abuse installer campaigns begins, exploiting Atera's no-verification free trial signup
  • Israeli university compromised via Syncro MSI installer combined with an encrypted RAR archive; Atera Agent abuse campaign tapers off around this time
  • Diplomatic-impersonation campaign (Omani foreign-ministry lures) targets foreign ministries and UN-affiliated organizations
  • Israeli IT services provider compromised via Rust-compiled payload (PhotoAcq.log), marking accelerated shift from commodity RMM tools to purpose-built RustyWater malware
  • Central Asia telecommunications sector targeted with a Cybersecurity.doc macro dropper
  • Genians Security Center publishes chronology report on ongoing MuddyWater APT attacks and RMM-tool abuse TTPs

Sources cited for MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate

Threats related to MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate

Detection coverage for TL-2026-1530

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1530 across Splunk SPL, Microsoft KQL and Sigma, covering 78 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats