MuddyWater
MITRE G0069Also known as GreenGolf, Mango Sandstorm, SeedWorm, Boggy Serpens, TEMP.Zagros, Static Kitten, TA450
Reports
19
First seen
Nov 6, 2025
Last seen
Jul 23, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×1×3
Israel×3
United States×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×13T1190 Exploit Public-Facing Application ×8T1087 Account Discovery ×6T1133 External Remote Services ×5T1003 OS Credential Dumping ×5T1078 Valid Accounts ×5T1566.002 Phishing: Spearphishing Link ×5T1486 Data Encrypted for Impact ×5T1041 Exfiltration Over C2 Channel ×5T1219 Remote Access Software ×5T1059.001 PowerShell ×5T1195 Supply Chain Compromise ×4
Indicators
filename ×48cve ×33ip_v4 ×16domain ×10hash_sha256 ×6registry_key ×3hash_md5 ×2url ×1hash_sha1 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-34291 (exploited)CVE-2026-33017 (exploited)CVE-2026-0770 (exploited)CVE-2026-5027 (exploited)CVE-2026-21445 (exploited)CVE-2025-48595 (exploited)CVE-2025-52691 (exploited)CVE-2025-54068 (exploited)CVE-2025-55182 (exploited)CVE-2025-59718 (exploited)CVE-2025-59719 (exploited)CVE-2025-68613 (exploited)CVE-2025-9316 (exploited)CVE-2026-0300 (exploited)CVE-2026-20230 (exploited)CVE-2026-22719 (exploited)CVE-2026-28318 (exploited)CVE-2026-34926 (exploited)CVE-2026-41089 (exploited)CVE-2026-4670
Recent reports
High