#MuddyWater
Little Brook Band
Creedence Muddywater Revival
Sly and the Dysfunctional Family Stone
October 14, 2025 at 6:40 PM
The Ctrl-Alt-Intel team has dumped the content of misconfigured command and control servers linked to the MuddyWater Iranian APT, aka Static Kitten, Mango Sandstorm, Earth Vetala, Seedworm, and TA450

ctrlaltintel.com/threat%20res...
MuddyWater Exposed: Inside an Iranian APT operation
MuddyWater espionage campaign exposed
ctrlaltintel.com
March 5, 2026 at 6:28 PM
#ESETresearch discovered a new #MuddyWater campaign targeting critical infrastructure in 🇮🇱 Israel and 🇪🇬 Egypt, using a new backdoor – MuddyViper – and a variety of post-compromise tools www.welivesecurity.com/en/eset-rese... 1/7
MuddyWater: Snakes by the riverbank
MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook.
www.welivesecurity.com
December 2, 2025 at 11:42 AM
Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign
Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign
thehackernews.com
October 22, 2025 at 7:22 PM
Ralph M Larmann, The Saturated Solution, 2017. Acrylic on canvas, 40 x 60 inches. Courtesy of the artist #art #painting #artsky #Jackson #FrenchQuarter #flooding #sealevelrise #hurricanesky #catfish #waterscape #Ralph #Larmann #Evansville #Indiana #river #NewOrleans #hurricane #climate #muddywater
March 24, 2025 at 10:32 AM
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor thehackernews.com/2026/03/iran...
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-linked MuddyWater hackers breached U.S. networks with new Dindoor malware as regional cyber attacks escalate amid Middle East conflict.
thehackernews.com
March 7, 2026 at 11:35 PM
January 28, 2025 at 7:45 PM
Credence Muddywater Revival
August 13, 2025 at 11:25 PM
MuddyWater Uses Compromised Mailboxes in Global Phishing Campaign www.infosecurity-magazine.com/news/muddywa...
MuddyWater Uses Compromised Mailboxes in Global Phishing Campaign
Group-IB has uncovered a phishing campaign by Iran-linked MuddyWater, exploiting compromised emails for foreign intelligence
www.infosecurity-magazine.com
October 24, 2025 at 7:12 AM
Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
Iran-linked APT MuddyWater targeted U.S. organizations, deploying the new Dindoor backdoor across sectors including banks, airports, and nonprofits.
securityaffairs.com
March 6, 2026 at 8:39 PM
Creedence Muddywater Stagnation
Slightly diminish a band: About as Good as Ezra
August 13, 2025 at 11:55 AM
State-sponsored Iranian hacker group MuddyWater has targeted more than 100 government entities in attacks that deployed version 4 of the Phoenix backdoor.
Iranian hackers targeted over 100 govt orgs with Phoenix backdoor
State-sponsored Iranian hacker group MuddyWater has targeted more than 100 government entities in attacks that deployed version 4 of the Phoenix backdoor.
www.bleepingcomputer.com
October 22, 2025 at 9:19 PM
New work work:
Sophos MDR / X-Ops tracking an activity cluster matching previously reported activity by the Iranian threat actor "MuddyWater" against an Israeli company.
news.sophos.com/en-us/2024/1...
Sophos MDR blocks and tracks activity from probable Iranian state actor “MuddyWater”
Sophos MDR has observed a new campaign that uses targeted phishing to entice the target to download a legitimate remote machine management tool to dump credentials. We believe with moderate confide…
news.sophos.com
November 20, 2024 at 6:13 PM
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor share.google/R52KJpKEL7Oi...
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-linked MuddyWater hackers breached U.S. networks with new Dindoor malware as regional cyber attacks escalate amid Middle East conflict.
share.google
March 7, 2026 at 6:06 PM
New research from Broadcom's Symantec and Carbon Black Threat Hunter Team has discovered evidence of an Iranian hacking group embedding itself in several U.S. companies' networks, including banks, airports, non-profit, and the Israeli arm of a software company. thehackernews.com/2026/03/iran...
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-linked MuddyWater hackers breached U.S. networks with new Dindoor malware as regional cyber attacks escalate amid Middle East conflict.
thehackernews.com
March 8, 2026 at 1:37 PM
Ghosts from MuddyWater are the silent, persistent access planted during the 2025 war, marking their evolution from noisy hackers to a global strategic threat.

Read the article:
decodedintel.com/ghosts-from-...

#MuddyWater #Iran #Israel #Cybersecurity #ThreatIntelligence #Geopolitics
Ghosts From MuddyWater | Decoded Intel
Ghosts from MuddyWater are the silent, persistent access planted during the 2025 war, marking their evolution from noisy hackers to a global strategic threat.
decodedintel.com
November 28, 2025 at 7:48 AM
Slightly diminish a band:
Creedence Muddywater Revival
Slightly diminish a band:

The Jackson 4
Slightly diminish a band:

Some Doubt
August 13, 2025 at 7:07 PM
A new Iranian cyber-espionage operation (MuddyWater) has targeted more than 100 government entities across the MENA region.

The campaign spread a new backdoor named Phoenix

www.group-ib.com/blog/muddywa...
October 23, 2025 at 10:32 AM
Selon Nozomi Networks, spécialisée dans la sécurisation des technologies opérationnelles (OT) pour les infrastructures critiques, les pirates informatiques soutenus par l'État iranien semblent avoir intensifié leurs attaques contre les industries américaines au cours des deux derniers mois.
Threat Actor Activity Related to the Iran Conflict
Nozomi Networks Labs has observed a 133% increase in cyberattacks coming from well-known Iranian threat actors including MuddyWater, APT33, OilRig, CyberAv3ngers.
www.nozominetworks.com
July 14, 2025 at 3:45 AM
MuddyWater still abuse internxt and PDQ Agent:
share.ue.internxt[.]com/d/sh/file/12cdc548-c660-47f9-b4da-50485205b66e/68a6372f00013bb7f93e78eb265a59bffb985206e15cfa5d3a67e38645998a02
Mivchar.zip
86f6efd875aba984f314cbc858fb8339
Mivchar.msi
cd6e918bbcd562df59a563b68a82821c
March 23, 2025 at 9:18 AM
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors thehackernews.com/2026/01/mudd...
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
MuddyWater launched RustyWater, a Rust-based RAT, via spear-phishing Word macros targeting Middle East organizations.
thehackernews.com
January 11, 2026 at 10:53 AM
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
thehackernews.com
March 6, 2026 at 11:23 AM