logo

MuddyWater__2020__Reviving_MuddyC3_Used_by_MuddyWater_IRAN_APT.pdf

ID: 47cfadc9-a946-4cb7-a6a2-648168282289

STIX ID: report--47cfadc9-a946-4cb7-a6a2-648168282289

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2020-01-14

Last Modified Date: 2020-01-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This article analyzes a leaked MuddyC3 C2 and PowerShell agent used by the MuddyWater APT, documents how the C2 serves payloads, the agent registration/command/result endpoints, and demonstrates post-exploitation actions (credential dumping with Mimikatz and domain escalation). It also describes the leak/sale of MuddyWater tools by a group called GreenLeakers and includes IPs, payload examples, and notes about AV detection and planned encryption improvements.