Muddying the Water: Targeted Attacks in the Middle EastPalo Alto Unit 42·Nov 14, 21:00 UTC · Nov 14, 2017Data breach57
Iranian linked conglomerate MuddyWater comprised of regionally focused subgroupsCisco Talos·Mar 10, 13:02 UTC · Mar 10, 2022Ransomware57
Similarities and differences between MuddyWater and APT34Security Affairs·Jun 27, 05:33 UTC · Jun 27, 2019Threat actor57
MuddyWater strikes Israel with advanced MuddyViper malwareSecurity Affairs·Dec 2, 15:19 UTC · Dec 2, 2025Malware42
I know what you did last summer, MuddyWater blending in the crowdKaspersky Securelist·Apr 29, 08:00 UTC · Apr 29, 2019Exploit / PoC57
Iranian APT MuddyWater targets Turkish users via malicious PDFs, executablesCisco Talos·Jan 31, 13:00 UTC · Jan 31, 2022Ransomware57
USCYBERCOM: MuddyWater APT is linked to Iran's MOIS intelligenceSecurity Affairs·Jan 13, 08:26 UTC · Jan 13, 2022VulnerabilityCVE-2020-068847
MuddyWater APT group is back with updated TTPsSecurity Affairs·Dec 11, 10:23 UTC · Dec 11, 2022Threat actor57
Iran-linked MuddyWater APT group campaign targets Turkish entitiesSecurity Affairs·Feb 1, 11:09 UTC · Feb 1, 2022Threat actor57
Recent MuddyWater-associated BlackWater campaign shows signs of new antiCisco Talos·May 20, 15:00 UTC · May 20, 2019Threat actor57
MuddyWater deploys new DCHSpy variants amid IranSecurity Affairs·Jul 21, 18:39 UTC · Jul 21, 2025Exploit / PoC57
Iranian MuddyWater Upgrades Arsenal With New Custom BackdoorInfosecurity Magazine·Jul 16, 15:00 UTC · Jul 16, 2024Malware42
Who is behind MuddyWater in Middle East? Likely a politicallySecurity Affairs·Nov 17, 13:42 UTC · Nov 17, 2017Data breach57
From MuddyC3 to PhonyC2: Iran's MuddyWater Evolves with a New Cyber WeaponThe Hacker News·Jul 2, 06:15 UTC · Jul 2, 2023Malware42
'MuddyWater' spies suspected in attacks against Middle East governments, telecomsCyberScoop·Oct 21, 13:53 UTC · Oct 21, 2020Exploit / PoC in the wild60
A new MuddyWater Campaign spreads Powershell-based PRBSecurity Affairs·Jun 15, 20:22 UTC · Jun 15, 2018Threat actor57
MuddyWater cyber campaign adds new backdoors in latest wave of attacksHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2025Malware42
MuddyWater has been spotted targeting two Israeli entitiesSecurity Affairs·Nov 3, 09:03 UTC · Nov 3, 2023Malware42
Israeli Entities Under Attack By MuddyWater’s Advanced TacticsInfosecurity Magazine·Nov 2, 17:00 UTC · Nov 2, 2023Threat actor60
Researchers uncover new MuddyWater targeting of government, telecom entitiesCyberScoop·Jun 7, 16:42 UTC · Jun 7, 2019Ransomware in the wild60
Iranian cyber espionage disguised as a Chaos Ransomware attackSecurity Affairs·May 6, 14:19 UTC · May 6, 2026Ransomware57
US and UK details a new Python backdoor used by MuddyWater APTSecurity Affairs·Feb 25, 06:20 UTC · Feb 25, 2022Malware55
MuddyWater BlackWater campaign used new antiSecurity Affairs·May 21, 05:32 UTC · May 21, 2019Threat actor57
Middle East-linked hacking group is working hard to mask its movesCyberScoop·May 20, 22:26 UTC · May 20, 2019Exploit / PoC60
Iran-linked MuddyWater deploys Dindoor malware against U.S. organizationsSecurity Affairs·Mar 6, 20:05 UTC · Mar 6, 2026Malware55
Iran-Linked MuddyWater Targets 100+ Organizations in Global Espionage CampaignThe Hacker News·Dec 8, 06:03 UTC · Dec 8, 2025Threat actor57
MuddyWater Uses Compromised Mailboxes in Global Phishing CampaignInfosecurity Magazine·Oct 22, 16:00 UTC · Oct 22, 2025Threat actor60
Iranian MuddyWater Hackers Adopt New C2 Tool 'DarkBeatC2' in Latest CampaignThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2024Threat actor57
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware AttackThe Hacker News·May 7, 08:46 UTC · May 7, 2026Ransomware57
Iran’s MuddyWater Hackers Hit US Firms with New 'Dindoor' BackdoorInfosecurity Magazine·Mar 6, 15:15 UTC · Mar 6, 2026Malware42
Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing AttacksThe Hacker News·Mar 26, 03:55 UTC · Mar 26, 2024Phishing & fraud42
MuddyWater Uses SimpleHelp to Target Critical Infrastructure FirmsInfosecurity Magazine·Apr 18, 17:00 UTC · Apr 18, 2023Threat actor60
US Cyber Command Links 'MuddyWater' Hacking Group to Iranian IntelligenceThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2022VulnerabilityCVE-2020-147247
Iran-Linked MuddyWater Poses as Ransomware Gang to Mask EspionageInfosecurity Magazine·Jun 24, 12:00 UTC · Jun 24, 2026Ransomware57
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor BackdoorThe Hacker News·Mar 9, 06:40 UTC · Mar 9, 2026Malware in the wildCVE-2017-7921CVE-2023-6895CVE-2021-36260+2 CVEs60