MuddyWater__2022__Cisco_Talos_Intelligence_Group_-_Comprehensive_Threat_Intelligence_Iranian_APT_MuddyWater_targets_Turkish_users_via_malicious_PDFs_executables.pdf
ID: 96a49499-de5b-4b56-a64f-3c5635287243
STIX ID: report--96a49499-de5b-4b56-a64f-3c5635287243
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2022-02-10
Last Modified Date: 2022-02-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos details an active MuddyWater (Iranian APT) campaign targeting Turkish government and private entities using spear‑phishing PDFs that link to malicious Excel docs or executables which deploy obfuscated PowerShell and VBS components, achieve persistence via HKCU Run keys and living‑off‑the‑land binaries, and employ canary tokens for tracking/anti‑analysis; the report includes technical TTPs and extensive IOCs (IPs, URLs, hashes) for detection and mitigation.
