Muddying the Water: Targeted Attacks in the Middle EastPalo Alto Unit 42·Nov 14, 21:00 UTC · Nov 14, 2017Data breach57
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroupsCisco Talos·Mar 10, 13:02 UTC · Mar 10, 2022Ransomware57
Similarities and differences between MuddyWater and APT34Security Affairs·Jun 27, 05:33 UTC · Jun 27, 2019Threat actor57
MuddyWater strikes Israel with advanced MuddyViper malwareSecurity Affairs·Dec 2, 15:19 UTC · Dec 2, 2025Malware42
I know what you did last summer, MuddyWater blending in the crowdKaspersky Securelist·Apr 29, 08:00 UTC · Apr 29, 2019Exploit / PoC57
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executablesCisco Talos·Jan 31, 13:00 UTC · Jan 31, 2022Ransomware57
USCYBERCOM: MuddyWater APT is linked to Iran's MOIS intelligenceSecurity Affairs·Jan 13, 08:26 UTC · Jan 13, 2022VulnerabilityCVE-2020-068847
MuddyWater APT group is back with updated TTPsSecurity Affairs·Dec 11, 10:23 UTC · Dec 11, 2022Threat actor57
Iran-linked MuddyWater APT group campaign targets Turkish entitiesSecurity Affairs·Feb 1, 11:09 UTC · Feb 1, 2022Threat actor57
Recent MuddyWater-associated BlackWater campaign shows signs of new antiCisco Talos·May 20, 15:00 UTC · May 20, 2019Threat actor57
MuddyWater deploys new DCHSpy variants amid IranSecurity Affairs·Jul 21, 18:39 UTC · Jul 21, 2025Exploit / PoC57
Iranian MuddyWater Upgrades Arsenal With New Custom BackdoorInfosecurity Magazine·Jul 16, 15:00 UTC · Jul 16, 2024Malware42
Who is behind MuddyWater in Middle East? Likely a politicallySecurity Affairs·Nov 17, 13:42 UTC · Nov 17, 2017Data breach57
From MuddyC3 to PhonyC2: Iran's MuddyWater Evolves with a New Cyber WeaponThe Hacker News·Jul 2, 06:15 UTC · Jul 2, 2023Malware42
A new MuddyWater Campaign spreads Powershell-based PRBSecurity Affairs·Jun 15, 20:22 UTC · Jun 15, 2018Threat actor57
MuddyWater cyber campaign adds new backdoors in latest wave of attacksHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2025Malware42
MuddyWater has been spotted targeting two Israeli entitiesSecurity Affairs·Nov 3, 09:03 UTC · Nov 3, 2023Malware42
Iranian cyber espionage disguised as a Chaos Ransomware attackSecurity Affairs·May 6, 14:19 UTC · May 6, 2026Ransomware57
MuddyWater BlackWater campaign used new antiSecurity Affairs·May 21, 05:32 UTC · May 21, 2019Threat actor57
Iran-Linked MuddyWater Targets 100+ Organizations in Global Espionage CampaignThe Hacker News·Dec 8, 06:03 UTC · Dec 8, 2025Threat actor57
Iranian MuddyWater Hackers Adopt New C2 Tool 'DarkBeatC2' in Latest CampaignThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2024Threat actor57
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware AttackThe Hacker News·May 7, 08:46 UTC · May 7, 2026Ransomware57
Iran’s MuddyWater Hackers Hit US Firms with New 'Dindoor' BackdoorInfosecurity Magazine·Mar 6, 15:15 UTC · Mar 6, 2026Malware42
Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing AttacksThe Hacker News·Mar 26, 03:55 UTC · Mar 26, 2024Phishing & fraud42
US Cyber Command Links 'MuddyWater' Hacking Group to Iranian IntelligenceThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2022VulnerabilityCVE-2020-147247
Iran-Linked MuddyWater Poses as Ransomware Gang to Mask EspionageInfosecurity Magazine·Jun 24, 12:00 UTC · Jun 24, 2026Ransomware57
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIPThe Hacker News·Feb 23, 17:21 UTC · Feb 23, 2026Vulnerability42
Iran-linked 'MuddyWater' carrying out digital attacks worldwide, U.S. warnsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Ransomware57
Beers with Talos, Ep. #116: Let's wade into the MuddyWater filled with VipersCisco Talos·Feb 11, 17:07 UTC · Feb 11, 2022Malware42
MuddyWater Hackers Target Asian and Middle East Countries with Updated TacticsThe Hacker News·Dec 10, 05:30 UTC · Dec 10, 2022Malware42
Iran's MuddyWater Hacker Group Using New Malware in Worldwide Cyber AttacksThe Hacker News·Feb 26, 07:01 UTC · Feb 26, 2022Malware in the wild157
Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber AttacksThe Hacker News·Apr 17, 11:00 UTC · Apr 17, 2025Malware42
Iran-Based Hackers Caught Carrying Out Destructive Attacks Under Ransomware GuiseThe Hacker News·Apr 8, 14:27 UTC · Apr 8, 2023Ransomware57
Iran-Linked Seedworm APT target orgs in the Middle EastSecurity Affairs·Dec 15, 10:56 UTC · Dec 15, 2021Ransomware57
Alleged MuddyWater attack downloads a PowerShell script from GitHubSecurity Affairs·Jan 4, 08:49 UTC · Jan 4, 2021Malware142