Overview 15,674 indicators
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.
| domain | 15,243 | G0069-domain.txt |
| url | 286 | G0069.json |
| ipv4 | 107 | G0069.json |
| url_path | 38 | G0069.json |
Techniques 68 ATT&CK
Open in ATT&CK Navigator → or download the layer (68 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.004 LSA Secrets
- T1003.005 Cached Domain Credentials
- T1016 System Network Configuration Discovery
- T1027.003 Steganography
- T1027.004 Compile After Delivery
- T1027.010 Command Obfuscation
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.006 Python
- T1059.007 JavaScript
- T1071.001 Web Protocols
- T1074.001 Local Data Staging
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1090 Proxy
- T1090.002 External Proxy
- T1102.002 Bidirectional Communication
- T1104 Multi-Stage Channels
- T1105 Ingress Tool Transfer
- T1113 Screen Capture
- T1132.001 Standard Encoding
- T1137.001 Office Template Macros
- T1140 Deobfuscate/Decode Files or Information
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1204.004 Malicious Copy and Paste
- T1210 Exploitation of Remote Services
- T1218.003 CMSTP
- T1218.005 Mshta
- T1218.011 Rundll32
- T1219.002 Remote Desktop Software
- T1518 Software Discovery
- T1518.001 Security Software Discovery
- T1534 Internal Spearphishing
- T1547.001 Registry Run Keys / Startup Folder
- T1548.002 Bypass User Account Control
- T1552.001 Credentials In Files
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1559.001 Component Object Model
- T1559.002 Dynamic Data Exchange
- T1560.001 Archive via Utility
- T1566 Phishing
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1567.002 Exfiltration to Cloud Storage
- T1571 Non-Standard Port
- T1573.001 Symmetric Cryptography
- T1574.001 DLL
- T1583.001 Domains
- T1583.006 Web Services
- T1588.001 Malware
- T1588.002 Tool
- T1590.004 Network Topology
- T1684.001 Impersonation
- T1685 Disable or Modify Tools
Software 21
- Mimikatz
- PowerSploit
- POWERSTATS
- Koadic
- LaZagne
- Empire
- SHARPSTATS
- CrackMapExec
- ConnectWise
- RemoteUtilities
- Out1
- Small Sieve
- STARWHALE
- Rclone
- PowGoop
- Mori
- DCHSpy
- MuddyViper
- Fooder
- Tsundere Botnet
- LP-Notes
Principal sources 233 reports
Ranked by how many of this actor's indicators each report brought in.
- 10,536security.com/threat-intelligence/iran-seedworm-elect…
- 10,536virustotal.com/gui/ip-address/192.124.216.133/relations
- 10,536virustotal.com/gui/ip-address/217.71.204.197/relations
- 10,536virustotal.com/gui/ip-address/57.129.117.19/relations
- 5,311x.com/phatomcandle/status/2079989870622298451
- 145twitter.com/xiaocaiccc/status/1249586935275778048
- 145virustotal.com/gui/file/bf696397784b22f8e891dd0627dce7…
- 29deepinstinct.com/blog/muddyc2go-latest-c2-framework-used…
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 15,674 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 15,674. Complete: G0069.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
security.com/threat-intelligence/iran-seedworm-elect… · virustotal.com/gui/ip-address/192.124.216.133/relations · virustotal.com/gui/ip-address/217.71.204.197/relations · virustotal.com/gui/ip-address/57.129.117.19/relations
1509736.xyz 192-124-216-133.cprapid.com 208471.xyz 2317840.xyz 235718.xyz 330587.xyz 4107582.xyz 5712038.xyz 615782.xyz 647193.xyz 672806.xyz 728451.xyz 7564928.xyz 7614309.xyz 7639201.xyz 8734510.xyz 8942763.xyz 896240.xyz 907351.xyz 9823501.xyz abjwar.sa.com adfxzzz.mypi.co admin.buyalenovo.com advdser.shop aecbxzbc.mypi.co aedfxxv.mypi.co aefrgrgs.mypi.co aeren.pw aerivon.sa.com aerrxcc.mypi.co aet4.mypi.co aexbn.mypi.co afstmood.sa.com ahndmna.sa.com akishahin.za.com aldhahin.ru.com alisahhin.za.com alisnahin.za.com alistahin.za.com aloshahin.za.com alphaplaza.mypi.co alramiqw.sa.com alsbahin.ru.com alsgahin.ru.com alshabin.ru.com alshahkn.ru.com alshahon.ru.com alshanin.ru.com alshshin.ru.com alshzhin.ru.com alsihahin.za.com alsnahin.ru.com alstahin.ru.com amberfaith.mypi.co amberlaser.mypi.co amberplace.mypi.co ancdtaer.mypi.co applunar.space apshahin.ru.com aqualotus.mypi.co aquasugar.mypi.co aquawater.mypi.co aservbt.mypi.co askend.pw astuteifwave.mypi.co astutelunar.mypi.co astuteofsave35.mypi.co astuteonsoft352.mypi.co astuterack192.mypi.co astuteskill273.mypi.co asxzcxx.mypi.co aueenoas.sa.com axbjytr.mypi.co axcbrt.mypi.co ayfkfdyty.mypi.co azur.surf azurefruit167.mypi.co azuremedia.mypi.co bafd.mypi.co bandeeo.sa.com bandizoo.sa.com barvoioha.za.com barvoioma.za.com barvoipna.za.com barvooina.za.com barvpiona.za.com basicpart.mypi.co basicspine.mypi.co basictrace.mypi.co basket.qpon bayso.store bchtjj.mypi.co bdgdr.mypi.co benndlva.za.com benpfit.pw bgcvh.mypi.co biotrona.digital birchhar.icu bjfdsdwa.mypi.co bjybn.mypi.co bkopatiks.za.com bkuyuii.mypi.co bkyffuty.mypi.co blackmark.mypi.co blanktrack.mypi.co blazecraft564.mypi.co blazeentry.mypi.co blazemedia.mypi.co bluebyaxis.mypi.co blueflask775.mypi.co blueshell.mypi.co bluetryspiral.mypi.co bmfkorea.za.com bmipatiks.za.com bmooatiks.za.com bmopagiks.za.com bmopaitks.za.com bmopatoks.za.com bmopatuks.za.com bmopayiks.za.com bmopqtiks.za.com bmopstiks.za.com bmoptaiks.za.com bmopztiks.za.com bmrklrea.za.com bnhyy.mypi.co bnjkioer.mypi.co bnopatiks.za.com bnrtvc.mypi.co bnry6.mypi.co boldflare817.mypi.co boldplate.mypi.co boorato.sa.com boostpulse.mypi.co boouras.ru.com borakosa.ru.com boreyas.sa.com bourati.za.com bqrvoiona.za.com brainstom.shop bravealltime.mypi.co bravebay.mypi.co bravepaytruck.mypi.co bravetoview.mypi.co bravoiona.za.com breezay.surf bridke.cyou brieam.online brightlink.mypi.co brightport316.mypi.co brighttable686.mypi.co briskcheck70.mypi.co briskgrain.mypi.co briskstore.mypi.co briskteam.mypi.co brnageza.sa.com btnagezq.sa.com btnaheza.sa.com btnaneza.sa.com buni.pw buplder.store bvchdtft.mypi.co bvcnjtdrt.mypi.co bxfshrst.mypi.co bynageza.sa.com c0luselephant.sa.com cabrmano.ru.com cadmiies.click calmdrill.mypi.co calmnospot.mypi.co candeeo.sa.com candeio.sa.com candizoo.sa.com candteko.za.com cawateoa.sa.com cblocker.ru.com ccblocker.ru.com ccxblocker.sa.com cdblocker.ru.com cdxblocker.sa.com ceagth.space cegaasmore.sa.com cenomgg.za.com cfetavae.click chasedemo.online chauter.pw chgtd.mypi.co chiefengine.mypi.co chiefgaze591.mypi.co chiefpanel124.mypi.co chimastoz.click choire.store civicdish.mypi.co civicrack.mypi.co civilpixel.mypi.co civilquota.mypi.co civilrobot319.mypi.co cleverbase92.mypi.co clevercode.mypi.co clevermake.mypi.co cleverstaff.mypi.co cleverthesync828.mypi.co clipify.pw clluselephant.ru.com clpuselephant.za.com cluselephant.ru.com cluselephant.za.com cn45n.mypi.co cndhtt.mypi.co coalninethread.mypi.co commog.space constrct.sbs cooleagle.mypi.co coolgamma853.mypi.co coolgleam846.mypi.co coolonroot.mypi.co cooltower.mypi.co coqtume.online coralindex677.mypi.co coralscreen.mypi.co correlaton.cyou coset.surf costgme.shop cottbu.online couitry.qpon cpl7selephant.ru.com cpl7selephant.sa.com cplhselephant.sa.com cpljselephant.za.com cplkselephant.sa.com cplkselephant.za.com cplselephant.ru.com cplselephant.sa.com cplsuelephant.za.com cpluaelephant.ru.com cpluelephant.ru.com cpluelephant.sa.com cplus3lephant.sa.com cplusdlephant.sa.com cpluseelphant.sa.com cpluseephant.ru.com cpluseephant.sa.com cplusel3phant.ru.com cplusel3phant.za.com cplusel4phant.za.com cpluseldphant.ru.com cpluseldphant.za.com cplusele0hant.sa.com cpluselehant.sa.com cpluselehpant.za.com cpluselelhant.ru.com cpluselepahnt.za.com cpluselepant.sa.com cpluselepgant.ru.com cpluselepgant.za.com cpluselephabt.ru.com cpluselephaht.ru.com cpluselephajt.ru.com cpluselephamt.ru.com cpluselephan.sa.com cpluselephan.za.com cpluselephan5.ru.com cpluselephan5.za.com cpluselephan6.ru.com cpluselephan6.sa.com cpluselephanf.ru.com cpluselephanf.sa.com cpluselephang.ru.com cpluselephang.sa.com cpluselephanh.ru.com cpluselephant.sa.com cpluselephant.za.com cpluselephany.ru.com cpluselephnt.sa.com cpluselephxnt.za.com cpluselephznt.ru.com cpluselephznt.za.com cpluselepjant.sa.com cpluselepphant.sa.com cpluselepuant.ru.com cpluselepuant.sa.com cpluselepuant.za.com cpluselepyant.ru.com cpluselepyant.sa.com cpluselfphant.za.com cplusellephant.sa.com cpluselpehant.sa.com cpluselpehant.za.com cpluselphant.sa.com creatvie.cfd crisphelix493.mypi.co crispmarsh75.mypi.co csgrv.mypi.co ctress.space customizatn.cyou cvdsgsrsa.mypi.co cvdthss.mypi.co cvfse.mypi.co cvhtdh.mypi.co cvkiytyur.mypi.co · 1,632 more in this batch, in the JSON
Further reading 248
- attack.mitre.org/groups/G0069
- blog.cloudflare.com/2026-threat-report
- blog.talosintelligence.com/2022/01/iranian-apt-muddywater-targets-…
- falconfeeds.io/blogs/the-digital-redoubt-irans-nationa…
- hunt.io/blog/iranian-apt-infrastructure-state-a…
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- reaqta.com/2017/11/muddywater-apt-targeting-middle…
- researchcenter.paloaltonetworks.com/2017/11/unit42-muddying-the-water-targe…
- anomali.com/blog/probable-iranian-cyber-actors-stat…
- cisa.gov/uscert/ncas/alerts/aa22-055a
- clearskysec.com/wp-content/uploads/2018/11/MuddyWater-O…
- clearskysec.com/wp-content/uploads/2019/06/Clearsky-Ira…
- cybercom.mil/Media/News/Article/2897570/iranian-inte…
- fireeye.com/blog/threat-research/2018/03/iranian-th…
- proofpoint.com/us/blog/threat-insight/around-world-90-…
- proofpoint.com/us/blog/threat-insight/security-brief-t…
- security.com/threat-intelligence/iran-cyber-threat-a…
- symantec.com/blogs/threat-intelligence/seedworm-espi…
- trendmicro.com/en_us/research/21/c/earth-vetala---mudd…
- welivesecurity.com/en/eset-research/muddywater-snakes-rive…
- app.any.run/tasks/46cc133c-f3c6-4834-b139-0020ebed1…
- blog.talosintelligence.com/2022/03/iranian-supergroup-muddywater.h…
- virustotal.com/gui/file/92cb75c15da69fd6ef9368c03fd500…
- lookout.com/threat-intelligence/article/lookout-dis…
- otx.alienvault.com/pulse/5e1747ff614f5a153bbc1c08
- virustotal.com/gui/file/f6569039513e261ba9c70640e6eb8f…
- twitter.com/MichalKoczwara/status/17897312348447499…
- unit42.paloaltonetworks.com/boggy-serpens-threat-assessment
- twitter.com/Marco_Ramilli/status/1390556742262665216
- virustotal.com/gui/file/ffbcafc28eb2e83603479882a17f04…
- twitter.com/Des00464472/status/1587279425200336896
- virustotal.com/gui/file/c23f17b92b13464a570f737a86c096…
- virustotal.com/gui/file/bb3f5b0faa1b98be3881ae2d59c7f4…
- virustotal.com/gui/ip-address/91.235.234.202/relations
- virustotal.com/gui/file/111f9e2228a6b6f663cda85f8211ee…
- twitter.com/dimitribest/status/1790089941856170152
- app.any.run/tasks/afe95446-ef52-4acb-a4fb-a76b636e8…
- app.any.run/tasks/733ad416-1e4d-455f-9236-b8cf2196f…
- virustotal.com/gui/file/c3afd5ce1ca50a38438bb5026cca27…
- virustotal.com/gui/file/4f839eac8204930ecc21a35476069d…
208 more, and the report behind every indicator, in G0069.json.