MuddyWater__2022__Cisco_Iranian-MuddyWater-regionally-focused-subgroups_03-10-2022.pdf
ID: a83419e5-49be-4f51-99c6-55a3d5b6576f
STIX ID: report--a83419e5-49be-4f51-99c6-55a3d5b6576f
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2022-03-10
Last Modified Date: 2022-03-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos reports that the Iran-linked APT MuddyWater operates as a conglomerate of regionally focused subgroups conducting persistent campaigns across Turkey, the Arabian Peninsula, Pakistan, Armenia and other regions; they deliver maldocs that drop script-based RATs (notably a WSF RAT named SloughRAT), VBS/JS/PowerShell downloaders, and leverage tools like Ligolo for reverse tunneling, with detailed technical analysis and IOCs provided to detect and mitigate these threats.
