Actor Profile

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS). The group has been active since at least 2017, conducting cyber espionage operations aligned with Iranian strategic interests. MuddyWater is motivated by intelligence collection targeting government entities, critical infrastructure, and private sector organizations that hold strategic value to Iranian national security objectives. The group is known for persistent targeting of Middle Eastern, European, and Asian entities, with a focus on long-term access and data exfiltration.

TTPs (Tactics, Techniques, Procedures)

The Q1 2026 campaign leveraged DLL side-loading (T1574.001) as the primary initial access vector. MuddyWater's known TTP arsenal includes spearphishing with attachments (T1566.001) and links (T1566.002), Office template injection (T1137.001), and malicious file execution (T1204.004). For execution, the group employs Windows Command Shell (T1059.003), WMI (T1047), and msiexec (T1218.005). Persistence and lateral movement are achieved through internal spearphishing (T1534) and inter-process communication (T1559.001). The group acquires tools (T1588.002) and domains (T1583.001), conducts network reconnaissance (T1590.004), performs OS credential dumping via LSA Secrets (T1003.004), and uses non-standard ports for C2 (T1571). Known malware families include POWERSTATS, SHARPSTATS, PowGoop, STARWHALE, Mori, and Small Sieve.

Targets & Patterns

The campaign targeted at least nine organizations across nine countries, focusing on industrial manufacturing, electronics manufacturing, education, public sector, financial services, and professional services sectors. This targeting pattern aligns with MuddyWater's historical focus on entities that possess strategic intelligence value—critical infrastructure for operational insights, educational institutions for research and intellectual property, financial services for economic intelligence, and public sector organizations for policy and diplomatic information. The multi-country scope suggests a broad intelligence collection mandate rather than tactical operations, consistent with MOIS tasking. The inclusion of manufacturing sectors indicates potential interest in supply chain mapping, industrial capabilities assessment, or technology transfer monitoring.

Historical Context

MuddyWater has maintained consistent operational tempo since 2017, with documented campaigns targeting Middle Eastern governments, European telecommunications, and Asian critical infrastructure. The group has evolved from primarily PowerShell-based tooling (POWERSTATS) to more sophisticated .NET frameworks (SHARPSTATS) and custom malware families. Previous campaigns have demonstrated persistent focus on credential harvesting, lateral movement within victim networks, and long-term access maintenance. The Q1 2026 campaign's use of DLL side-loading represents a tactical evolution, likely adopted to evade endpoint detection improvements that have reduced the effectiveness of macro-based and script-based initial access methods. This technique has been observed in MuddyWater's toolkit since at least 2021 but appears to have become a primary vector in recent operations.

Defensive Recommendations

  • Monitor for DLL side-loading (T1574.001) by detecting unexpected DLL loads from non-standard paths, particularly legitimate signed binaries loading DLLs from user-writable directories; implement application whitelisting and DLL search order hardening
  • Detect PowerShell and Windows Command Shell execution (T1059.003) with command-line logging (Sysmon Event ID 1, Windows Event ID 4688) and behavioral analytics for obfuscated scripts, base64 encoding, and download cradles
  • Implement WMI monitoring (T1047) via Sysmon Event ID 19-21 and Windows Event ID 5857-5861 to identify suspicious remote WMI execution and persistence mechanisms
  • Deploy network monitoring for non-standard port C2 traffic (T1571) and establish baseline profiles for legitimate application traffic; investigate unexpected outbound connections on high-numbered ports
  • Harden credential storage and monitor LSA Secrets access (T1003.004) using protected process light (PPL) for LSASS, Credential Guard, and detection rules for LSASS memory access by non-system processes

---

# Geopolitical Context

Geopolitical Context

MuddyWater, a threat actor widely assessed to be linked to Iran's Ministry of Intelligence and Security (MOIS), appears to have conducted a geographically dispersed espionage campaign in early 2026. The targeting of industrial manufacturing, electronics, education, public-sector, financial services, and professional services across nine countries is consistent with Iran's strategic intelligence collection priorities. The use of DLL side-loading—a technique previously observed in MuddyWater operations—suggests operational continuity despite prior public disclosures and sanctions. The breadth of sectoral and geographic targeting may indicate either opportunistic access development or coordinated intelligence requirements spanning economic, technological, and governmental domains. This activity occurs against a backdrop of ongoing regional tensions and Iran's documented interest in maintaining persistent access to foreign networks for strategic advantage.

State Actor Alignment

MuddyWater has been publicly attributed by the United States, the United Kingdom, and other governments to Iran's Ministry of Intelligence and Security (MOIS). The group has been subject to U.S. Treasury sanctions and FBI advisories. The continued operational tempo in Q1 2026 suggests that Iranian state-sponsored cyber operations remain active despite international pressure and attribution efforts. The multi-country scope may reflect tasking from Iranian intelligence services seeking insights into foreign industrial capabilities, financial systems, and government operations—objectives aligned with Iran's broader strategic interests in circumventing sanctions, monitoring adversaries, and acquiring dual-use technology.

Business Impacty pro region

The geographic dispersion across nine countries indicates a campaign with global reach, likely affecting organizations in the Middle East, Europe, Asia, and potentially North America. For European entities, this activity underscores the persistent threat from Iranian cyber operations targeting critical sectors and government institutions, particularly as geopolitical friction over nuclear negotiations, regional proxy conflicts, and sanctions enforcement continues. The targeting of industrial and electronics manufacturing may have implications for supply chain security and intellectual property protection. Financial services targeting could support sanctions evasion research or economic intelligence gathering. Public-sector intrusions raise concerns about espionage against governmental decision-making processes. Organizations in affected regions should reassess their exposure to DLL side-loading techniques and review threat intelligence on MuddyWater tradecraft.

Forecast

If MuddyWater maintains its current operational pattern, additional intrusions using similar techniques are likely in the coming months, particularly if the group has successfully established persistent access within victim networks. Should geopolitical tensions involving Iran escalate—whether related to nuclear diplomacy, regional conflicts, or sanctions—the scope and intensity of Iranian cyber espionage operations may increase correspondingly. If Western governments issue further attributions or sanctions in response to this campaign, Iran may temporarily adjust tactics or infrastructure, though historical patterns suggest sustained long-term activity. Organizations in the targeted sectors and regions should anticipate continued reconnaissance and intrusion attempts, particularly those with strategic value to Iranian intelligence priorities.