logo

CISA Joint Cybersecurity Advisory - AA22-055A: Iranian Government-Sponsored Actors Conduct Cyber Operations

ID: 40af04d6-a162-4d07-b64d-6cbb209fcbe5

STIX ID: report--40af04d6-a162-4d07-b64d-6cbb209fcbe5

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2022-02-24

Last Modified Date: 2022-02-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This joint advisory from FBI, CISA, CNMF, NCSC‑UK, and NSA attributes widespread cyber espionage and malicious activity to the Iranian government‑sponsored APT "MuddyWater," describing their spearphishing and exploitation methods, multiple malware families (PowGoop, Small Sieve, Canopy/Starwhale, Mori, POWERSTATS), observed CVE exploitation, detailed TTPs and IOCs (IP addresses, file hashes, registry paths), and recommended mitigations and reporting procedures.