logo

MuddyWater__2022__CISA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations_02-24-2022.pdf

ID: e9f802f9-a15b-4194-8745-396a1fe99bfb

STIX ID: report--e9f802f9-a15b-4194-8745-396a1fe99bfb

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2022-02-24

Last Modified Date: 2022-02-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Joint Cybersecurity Advisory** attributing widespread cyber espionage and malicious operations to the Iranian government‑sponsored APT group MuddyWater (aka Earth Vetalia/Seedworm/Static Kitten), detailing their spearphishing campaigns, exploitation of known vulnerabilities (e.g., CVE‑2020‑1472, CVE‑2020‑0688), multiple malware families (PowGoop, Small Sieve, Canopy/Starwhale, Mori, POWERSTATS), extensive TTPs and IOCs (including numerous IP addresses, file hashes, registry keys and scripts), and providing detection, mitigation, and reporting guidance for affected organizations.