MuddyWater__2022__CISA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations_02-24-2022.pdf
ID: e9f802f9-a15b-4194-8745-396a1fe99bfb
STIX ID: report--e9f802f9-a15b-4194-8745-396a1fe99bfb
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2022-02-24
Last Modified Date: 2022-02-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Joint Cybersecurity Advisory** attributing widespread cyber espionage and malicious operations to the Iranian government‑sponsored APT group MuddyWater (aka Earth Vetalia/Seedworm/Static Kitten), detailing their spearphishing campaigns, exploitation of known vulnerabilities (e.g., CVE‑2020‑1472, CVE‑2020‑0688), multiple malware families (PowGoop, Small Sieve, Canopy/Starwhale, Mori, POWERSTATS), extensive TTPs and IOCs (including numerous IP addresses, file hashes, registry keys and scripts), and providing detection, mitigation, and reporting guidance for affected organizations.
