logo

MuddyWater__2022__Cisco_Talos_Intelligence_Group_-_Comprehensive_Threat_Intelligence_Iranian_APT_MuddyWater_targets_Turkish_users_via_malicious_PDFs_executables.pdf

ID: 96a49499-de5b-4b56-a64f-3c5635287243

STIX ID: report--96a49499-de5b-4b56-a64f-3c5635287243

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2022-02-10

Last Modified Date: 2022-02-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos details an active MuddyWater (Iranian APT) campaign targeting Turkish government and private entities using spear‑phishing PDFs that link to malicious Excel docs or executables which deploy obfuscated PowerShell and VBS components, achieve persistence via HKCU Run keys and living‑off‑the‑land binaries, and employ canary tokens for tracking/anti‑analysis; the report includes technical TTPs and extensive IOCs (IPs, URLs, hashes) for detection and mitigation.