logo

MuddyWater__2022__Mandiant_Telegram-Malware-Iranian-Activity_02-24-2022.pdf

ID: 2e447b69-d780-4e00-a716-62b957abdd30

STIX ID: report--2e447b69-d780-4e00-a716-62b957abdd30

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2022-02-25

Last Modified Date: 2022-02-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant documents an UNC3313 (likely TEMP.Zagros/MuddyWater) targeted intrusion against Middle Eastern government and technology organizations in 2021 that began with spear-phishing and rapid ScreenConnect deployment, and used custom backdoors (GRAMDOOR—Telegram-based, STARWHALE/STARWHALE.GO) alongside publicly available tools (CrackMapExec, LIGOLO, eHorus) for credential harvesting, lateral movement, tunneling, persistence, and C2; the report includes technical details, encoding schemes, persistence methods, MITRE ATT&CK mappings, YARA rules, and IOCs.