Home
Glossary
MuddyWater
Table of content
5 min
H2 title on one or more lines.
Share
By
Updated on
June 22, 2026

MuddyWater

MuddyWater, also known as MERCURY, Seedworm, or Static Kitten, is an Iranian threat actor with suspected ties to the Ministry of Intelligence and Security, active since at least 2017 and primarily targeting entities in the Middle East and beyond.

It has been active since at least 2017 and has targeted entities primarily in the Middle East, but also in Asia, Africa, Europe, and North America.

MuddyWater was observed using a backdoor called MuddyRot. Read our report for more information on this topic:

MuddyWater is typically used for intelligence collection, espionage, ransomware and destructive attacks.