MuddyWater__2020__Reviving_MuddyC3_Used_by_MuddyWater_IRAN_APT.pdf
ID: 47cfadc9-a946-4cb7-a6a2-648168282289
STIX ID: report--47cfadc9-a946-4cb7-a6a2-648168282289
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2020-01-14
Last Modified Date: 2020-01-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This article analyzes a leaked MuddyC3 C2 and PowerShell agent used by the MuddyWater APT, documents how the C2 serves payloads, the agent registration/command/result endpoints, and demonstrates post-exploitation actions (credential dumping with Mimikatz and domain escalation). It also describes the leak/sale of MuddyWater tools by a group called GreenLeakers and includes IPs, payload examples, and notes about AV detection and planned encryption improvements.
