logo

MuddyWater__2022__Cisco_Iranian-MuddyWater-regionally-focused-subgroups_03-10-2022.pdf

ID: a83419e5-49be-4f51-99c6-55a3d5b6576f

STIX ID: report--a83419e5-49be-4f51-99c6-55a3d5b6576f

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2022-03-10

Last Modified Date: 2022-03-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos reports that the Iran-linked APT MuddyWater operates as a conglomerate of regionally focused subgroups conducting persistent campaigns across Turkey, the Arabian Peninsula, Pakistan, Armenia and other regions; they deliver maldocs that drop script-based RATs (notably a WSF RAT named SloughRAT), VBS/JS/PowerShell downloaders, and leverage tools like Ligolo for reverse tunneling, with detailed technical analysis and IOCs provided to detect and mitigate these threats.