MuddyWater

☆ pin
MITRE G0069Also known as GreenGolf, Mango Sandstorm, SeedWorm, Boggy Serpens, TEMP.Zagros, Static Kitten, TA450
Reports
19
First seen
Nov 6, 2025
Last seen
Jul 23, 2026
Motivation
Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×3
Israel×3
United States×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566 Phishing ×13T1190 Exploit Public-Facing Application ×8T1087 Account Discovery ×6T1133 External Remote Services ×5T1003 OS Credential Dumping ×5T1078 Valid Accounts ×5T1566.002 Phishing: Spearphishing Link ×5T1486 Data Encrypted for Impact ×5T1041 Exfiltration Over C2 Channel ×5T1219 Remote Access Software ×5T1059.001 PowerShell ×5T1195 Supply Chain Compromise ×4

Indicators

filename ×48cve ×33ip_v4 ×16domain ×10hash_sha256 ×6registry_key ×3hash_md5 ×2url ×1hash_sha1 ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

Bleeping Computer
High

Iran War Cyber Threat Landscape | Midyear Assessment

SentinelOne Labs
High

AI Has Enhanced Iran's Asymmetric Playbook During the 2026 Conflict

Recorded Future Insikt
High

Iran-Linked Cavern Manticore Uses New C2 Framework to Target Israeli Organizations

The Hacker News
High

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

The Hacker News
High

Path traversal flaw in Langflow AI platform actively exploited

Bleeping Computer
High

Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

The Hacker News
Critical

Check Point Threat Intelligence Report – June 2025 Breaches, Vulnerabilities, and AI Threats

Check Point Research
High

MuddyWater Deploys DLL Side-Loading in Multi-Country Espionage Campaign

The Hacker News
Critical

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV Catalog

The Hacker News
High

Microsoft disrupts Fox Tempest code-signing service used by ransomware groups

CyberScoop
unrated

Check Point Research Threat Intelligence Report – 11 May

Check Point Research
High

The Iran War: Cyber Threat Landscape, Influence Operations, and Strategic Scenarios

Recorded Future Insikt
High

CERT-EU Cyber Brief March 2026 – Espionage, Supply-Chain Attacks, Iran Conflict Disruptions

CERT-EU Threat Intel
High

Cyber fallout from the Iran war: Threat actors, tactics, and resilience measures

ESET WeLiveSecurity
High

Unmasking an Attack Chain of MuddyWater: Iranian APT Intrusion Analysis

Huntress Blog
High

Cyber Brief December 2025: Espionage, Ransomware, and Infrastructure Attacks Across Europe and Beyond

CERT-EU Threat Intel
High

MuddyWater APT: New Fooder Loader and MuddyViper Backdoor Campaign Targeting Israel and Egypt

ESET WeLiveSecurity
High

ESET APT Activity Report Q2 2025–Q3 2025

ESET WeLiveSecurity

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.