CISA Joint Cybersecurity Advisory - AA22-055A: Iranian Government-Sponsored Actors Conduct Cyber Operations
ID: 40af04d6-a162-4d07-b64d-6cbb209fcbe5
STIX ID: report--40af04d6-a162-4d07-b64d-6cbb209fcbe5
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2022-02-24
Last Modified Date: 2022-02-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This joint advisory from FBI, CISA, CNMF, NCSC‑UK, and NSA attributes widespread cyber espionage and malicious activity to the Iranian government‑sponsored APT "MuddyWater," describing their spearphishing and exploitation methods, multiple malware families (PowGoop, Small Sieve, Canopy/Starwhale, Mori, POWERSTATS), observed CVE exploitation, detailed TTPs and IOCs (IP addresses, file hashes, registry paths), and recommended mitigations and reporting procedures.
