Threat Actor 🇮🇷 Iran

MuddyWater

Also known as: TEMP.Zagros · Static Kitten · Seedworm · MERCURY · COBALT ULSTER · G0069 · ATK51 · Boggy Serpens · Mango Sandstorm · TA450 · Earth Vetala

The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.

Indicators of Compromise 45

MITRE ATT&CK TTPs 32

Source Articles

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Iranian nation-state actors linked to Cavern (aka Cav3rn) C2 framework have evolved their infrastructure to blend malicious traffic with legitimate services, using DNS A-record queries to dynamically switch between direct HTTPS and Google Apps Script relays for command-and-control. A new module, HOLLOWGRAPH, abuses Microsoft 365 calendars via the Graph API to exfiltrate data and receive commands, with events scheduled far into the future to avoid detection. The framework uses a modular architecture with components like GoogleService.dll and rnp.dll, leveraging legitimate cloud services to evade perimeter defenses and maintain persistence.
hacker-news ·2w ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
Iran-linked threat actor Seedworm (also known as MuddyWater, Temp Zagros, Static Kitten) conducted a global espionage campaign in early 2026, breaching at least nine organizations across four continents, including a major South Korean electronics manufacturer. The attackers used DLL sideloading with legitimately signed binaries from Fortemedia and SentinelOne to execute malicious payloads, leveraging Node.js scripts to orchestrate PowerShell-based reconnaissance, credential theft, privilege escalation, and SOCKS5 reverse-proxy tunneling. Data exfiltration was performed via the public file-transfer service sendit[.]sh, blending malicious traffic with legitimate cloud services to evade detection. The campaign reflects an evolution in Seedworm’s tradecraft toward more disciplined and stealthy operations.
security-com ·3mo ago
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are conducting vishing attacks via Microsoft Teams, impersonating IT support staff to trick employees into granting remote access to corporate devices. These intrusions are part of campaign STAC4749, tracked by Sophos, which led to the deployment of Chaos ransomware in at least three organizations. The attackers used fake IT-themed domains and spoofed identities to initiate contact, then deployed remote management tools like RemSupp and PowerShell-based backdoors to establish persistence and move laterally. The campaign targeted primarily North American organizations, with attacks spanning from February to June 2026, and demonstrated rapid progression from initial access to ransomware encryption—sometimes within 17 hours.
bleeping-computer ·4w ago
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is deploying a new Rust-based backdoor named msaRAT that leverages Chrome or Edge browsers to route command-and-control (C2) traffic, evading detection by avoiding direct network connections. The malware uses the Chrome DevTools Protocol to control a headless browser session and establishes encrypted communication via WebRTC through Twilio TURN servers and a Cloudflare Workers endpoint. This dual-layer infrastructure hides the attacker's true C2 server and complicates traceback efforts, while also bypassing firewalls and allowlists by blending with legitimate web traffic.
bleeping-computer ·1mo ago
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph is a newly discovered espionage malware that leverages a compromised Microsoft 365 calendar as a covert command-and-control (C2) channel, hiding operator instructions and exfiltrated data within calendar events dated to 2050. The malware uses legitimate Microsoft Graph API traffic to avoid detection, communicating via encrypted attachments on future-dated events. It is associated with the Cavern backdoor framework and shows potential ties to Iranian-linked actors, though attribution remains unconfirmed. The small, targeted footprint suggests focused cyber espionage rather than broad criminal activity.
hacker-news ·1mo ago
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group linked to the Ministry of Intelligence and Security (MOIS), tracked as Cavern Manticore, has been using a new modular command-and-control (C2) framework named Cavern to target Israeli organizations, particularly in the IT and government sectors. The attack leverages DLL side-loading via SysAid's software update mechanism, deploying a trojanized DLL (uxtheme.dll) that communicates with a C2 server and downloads additional malicious modules. These modules enable reconnaissance, data theft, lateral movement, and tunneling, with a sophisticated .NET-based architecture using mixed compilation formats to hinder analysis. The group exploits trusted relationships in the software supply chain and has shifted from broad reconnaissance to targeted data exfiltration across Middle Eastern sectors.
hacker-news ·1mo ago