Netskope Threat Labs

MuddyWater

ATP Sandbox Adv. HeuristicsAVNetskope IPS

MuddyWater is a threat group associated with Iranian state sponsored activity that uses PowerShell and other living off the land techniques to conduct espionage. Its campaigns target government, telecommunications, and energy organizations across the Middle East and beyond, and its operators favor simple but effective tools that run through script interpreters and legitimate utilities. The group's tradecraft has grown more sophisticated over time, and its tooling continues to evolve around a core of script based persistence.

First seen
March 2022
Last seen
October 2026
Muddywater
Alert Name
ByteCode-MSIL.Trojan.MuddyWater
Document-Excel.Trojan.Muddywater
Document-Office.Downloader.MuddyWater
Document-Office.Trojan.MuddyWater
Document-Word.Downloader.MuddyWater
Document-Word.Dropper.Muddywater
Document-Word.Trojan.Muddywater
Document-Word.Trojan.MuddyWater
Email-MSG.Downloader.MuddyWater
Email-MSG.Trojan.MuddyWater