← Back to Actors
MuddyWater
MuddyWaterEarth VetalaMERCURYStatic KittenSeedwormTEMP.ZagrosMango SandstormTA450MuddyKrill
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at least 2017, [MuddyWater](https://attack.mitre.org/groups/G0069) has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. [MuddyWater](ht...
70
Techniques
66
Covered
4
Gaps
94%
Coverage
Coverage66/70
GAPS (4)
COVERED (66)
T1003.001LSASS Memory111 det.T1003.004LSA Secrets18 det.T1003.005Cached Domain Credentials12 det.T1016System Network Configuration Discovery41 det.T1027.003Steganography5 det.T1027.004Compile After Delivery10 det.T1027.010Command Obfuscation38 det.T1033System Owner/User Discovery62 det.T1036.005Match Legitimate Resource Name or Location45 det.T1041Exfiltration Over C2 Channel32 det.T1047Windows Management Instrumentation88 det.T1049System Network Connections Discovery23 det.T1053.005Scheduled Task100 det.T1057Process Discovery23 det.T1059.001PowerShell376 det.T1059.003Windows Command Shell87 det.T1059.005Visual Basic70 det.T1059.006Python53 det.T1059.007JavaScript64 det.T1071.001Web Protocols81 det.T1074.001Local Data Staging10 det.T1082System Information Discovery88 det.T1083File and Directory Discovery48 det.T1087.002Domain Account58 det.T1090Proxy49 det.T1090.002External Proxy8 det.T1102.002Bidirectional Communication16 det.T1105Ingress Tool Transfer191 det.T1113Screen Capture19 det.T1132.001Standard Encoding5 det.T1137.001Office Template Macros1 det.T1140Deobfuscate/Decode Files or Information58 det.T1190Exploit Public-Facing Application233 det.T1203Exploitation for Client Execution80 det.T1204.001Malicious Link11 det.T1204.002Malicious File461 det.T1204.004Malicious Copy and Paste9 det.T1210Exploitation of Remote Services37 det.T1218.003CMSTP21 det.T1218.005Mshta49 det.T1218.011Rundll3276 det.T1219Remote Access Tools46 det.T1219.002Remote Desktop Software53 det.T1518Software Discovery17 det.T1518.001Security Software Discovery11 det.T1534Internal Spearphishing264 det.T1547.001Registry Run Keys / Startup Folder53 det.T1548.002Bypass User Account Control84 det.T1552.001Credentials In Files62 det.T1555Credentials from Password Stores41 det.T1555.003Credentials from Web Browsers16 det.T1559.001Component Object Model17 det.T1559.002Dynamic Data Exchange1 det.T1560.001Archive via Utility27 det.T1562.001Disable or Modify Tools325 det.T1566Phishing1192 det.T1566.001Spearphishing Attachment1055 det.T1566.002Spearphishing Link1086 det.T1567.002Exfiltration to Cloud Storage31 det.T1571Non-Standard Port17 det.T1574.001DLL111 det.T1583.001Domains68 det.T1583.006Web Services1 det.T1588.001Malware2 det.T1588.002Tool13 det.T1685Disable or Modify Tools281 det.