Home
Glossary
MuddyWater
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
June 22, 2026

MuddyWater (aka MERCURY, Seedworm, Static Kitten) threat actor

MuddyWater is an Iranian state-sponsored cyber espionage group, assessed to operate as part of Iran's Ministry of Intelligence and Security (MOIS). Active since at least 2017, it conducts intelligence-gathering intrusions against government and private organizations, primarily in the Middle East but also across Asia, Africa, Europe, and North America. It is tracked under many names, including MERCURY, Seedworm, Static Kitten, Earth Vetala, TEMP.Zagros, and, in Microsoft's newer taxonomy, Mango Sandstorm. MITRE ATT&CK catalogs it as G0069. MuddyWater is known for a practical, adaptable style of operation: heavy use of PowerShell, living-off-the-land techniques, and, in particular, the abuse of legitimate remote monitoring and management (RMM) software to control compromised systems. This page covers the group's attribution and aliases, who it targets, how it operates, how its tooling has evolved, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.

Key takeaways

  • MuddyWater is an Iranian state-sponsored espionage group, assessed to operate as part of the Ministry of Intelligence and Security (MOIS), active since at least 2017.
  • It has many names. MERCURY, Seedworm, Static Kitten, Earth Vetala, TEMP.Zagros, and Mango Sandstorm all refer to the same actor, tracked by MITRE as G0069.
  • It targets government and strategic industry, including telecommunications, defense, oil and gas, and local government, primarily in the Middle East but also worldwide.
  • Its signature is RMM abuse and PowerShell. MuddyWater leans on spearphishing, PowerShell, and legitimate remote-management tools such as Atera and ScreenConnect to gain and keep access.
  • Its tooling keeps evolving. From the PowerShell backdoor POWERSTATS to custom implants like MuddyRot, the group adapts its methods to stay ahead of defenders.

Attribution and aliases

MuddyWater is attributed to the Iranian state. US Cyber Command has publicly identified it as a subordinate element within Iran's Ministry of Intelligence and Security (MOIS), and CISA and allied agencies have issued joint advisories on the group. This places its state link on a firm footing rather than industry assessment alone, and its intelligence-gathering focus is consistent with a state-directed espionage mission.

Because many vendors have tracked the group independently, it carries an unusually long list of names. The most common are below:

  • MuddyWater
  • MERCURY
  • Mango Sandstorm
  • Seedworm
  • Static Kitten
  • TEMP.Zagros
  • Earth Vetala
  • TA450

They all point to the same actor. As with other long-running groups, occasional differences between vendor clusters are normal, so analysts cross-reference reporting when researching it. A note on scope: some reporting indicates MuddyWater maps target networks and shares or sells that access to other Iranian threat groups, so its activity can overlap with, but should not be conflated with, other Iran-linked actors.

Who MuddyWater targets

MuddyWater's targeting reflects Iranian intelligence priorities and concentrates on organizations of strategic value. Its recurring targets include:

  • Government and local government bodies, a consistent focus across the regions it operates in.
  • Telecommunications, a sector that offers reach into communications and other networks.
  • Defense, oil and gas, and energy, reflecting geopolitical and economic intelligence interests.
  • Other private organizations, including finance and technology, particularly where they hold useful access or information.

Geographically the group concentrates on the Middle East, with frequent activity affecting countries such as the United Arab Emirates, Saudi Arabia, Turkey, Israel, Jordan, and others in the region, while also reaching organizations in Asia, Africa, Europe, and North America. Its activity has been observed to intensify around regional tensions and conflict.

How MuddyWater operates

MuddyWater favors accessible, adaptable tradecraft over rare or advanced exploits. It relies heavily on social engineering, scripting, and legitimate software, which lets its activity blend into normal administration. Its behavior maps onto the MITRE ATT&CK framework.

Stage Techniques Detail
Initial access Spearphishing, server exploitation Spearphishing with malicious attachments or links, often sent from previously compromised accounts to appear legitimate; exploitation of internet-facing servers such as Microsoft Exchange and SharePoint.
Execution PowerShell, VBScript, JavaScript, obfuscation Heavy use of PowerShell and scripting (VBScript, JavaScript), with obfuscation to hinder analysis.
Access & persistence RMM tool abuse, scheduled tasks, registry persistence Abuse of legitimate remote monitoring and management (RMM) tools such as Atera, ScreenConnect, and SimpleHelp; scheduled tasks and registry or template-based persistence.
Collection & exfiltration Credential dumping, lateral movement, cloud exfiltration Credential dumping, internal reconnaissance and lateral movement, and exfiltration over web protocols or cloud storage services.

Two traits define the group's style. First, its reliance on PowerShell and living-off-the-land techniques, using tools already present on a system, so that malicious activity resembles legitimate administration. Its long-running PowerShell backdoor, known as POWERSTATS, is a recurring example. Second, and most distinctive, is its abuse of legitimate RMM software. Rather than always deploying custom malware, MuddyWater has frequently installed commercial remote-management tools such as Atera and ScreenConnect on compromised hosts, using their normal remote-control features to maintain access and move data. Because these tools are legitimate and widely used by IT teams, their presence can be difficult to distinguish from authorized administration.

How MuddyWater's tooling has evolved

MuddyWater has steadily changed its toolkit while keeping the same overall approach. Its early operations leaned on the PowerShell backdoor POWERSTATS and a range of publicly available and scripting-based tools. Over time it shifted toward abusing legitimate RMM software as its first-stage foothold, which offered more capability than a simple script and blended in with normal IT activity. More recently, as defenders increased their monitoring of RMM abuse, the group has returned to custom implants in some campaigns, and has been observed adopting newer development languages for its malware. This willingness to switch between custom tools and legitimate software, depending on what evades detection, is a defining feature of the group and a reason it has remained active for years. One documented example of this shift is detailed in Sekoia's research below.

Sekoia's research on MuddyWater

Sekoia's TDR team has tracked MuddyWater's changing infection chains directly. In a 2024 campaign against Western and Middle Eastern entities, TDR found that the group had altered its approach: instead of relying on the legitimate Atera RMM tool as its first-stage validator, as it had in earlier campaigns, it deployed a new, previously undocumented custom implant that Sekoia analysts named MuddyRot (independently reported by Check Point as BugSleep). The delivery also shifted, with malicious links embedded inside PDF documents using course and webinar decoys rather than placed directly in emails. Sekoia assessed that heightened security-vendor monitoring of RMM abuse was a likely reason for the return to a custom tool, and noted that a group-specific implant, unlike widely used legitimate software, actually makes the actor easier for defenders to track. This kind of first-hand analysis, published with indicators, is what turns a shift in tradecraft into something defenders can detect.

How to defend against MuddyWater

Because MuddyWater relies on phishing, PowerShell, and legitimate tools rather than rare exploits, defense combines user and identity protection with behavioral monitoring:

  1. Harden against phishing. Strong email filtering, user awareness, and scrutiny of links, including those embedded in attachments such as PDFs, reduce the group's main route to initial access.
  2. Patch and monitor internet-facing servers. Because the group also exploits exposed Exchange and SharePoint servers, prompt patching and monitoring of these systems close a second common entry point.
  3. Control and monitor RMM software. Inventory which remote-management tools are authorized, alert on the installation or use of unexpected ones, and treat unsanctioned RMM activity as suspicious, since this is central to the group's tradecraft.
  4. Watch PowerShell and script activity. Enable PowerShell logging and monitor for obfuscated scripts and unusual scripting behavior, which are hallmarks of the group's living-off-the-land style.
  5. Use threat intelligence and hunt behaviorally. Tracking the group's known tooling, infrastructure, and current techniques, and hunting for the behaviors rather than fixed indicators, helps teams recognize its activity even as its tools change.

Expert insight: When the tool is legitimate

MuddyWater illustrates a challenge that defines a lot of modern intrusions: the actor rarely needs anything exotic. A phishing email from a real, compromised account, a PowerShell script, a copy of a remote-management tool that thousands of IT teams use every day, each element is either legitimate or looks legitimate. That is what makes the group effective. A blocklist of bad files does little against an attacker whose main tool is commercial software an organization might genuinely use, and whose scripts run through a utility built into the operating system.

This is where a CTI-led, behavior-focused approach earns its place, and where Sekoia's own work on the group is instructive. Sekoia is a European cybersecurity vendor whose in-house TDR team tracks actors such as MuddyWater, including shifts in how they deliver and control their intrusions, and that intelligence feeds the platform. Rather than treating the installation of a remote-management tool or a PowerShell execution as an isolated event, Sekoia's AI SOC platform correlates signals across endpoint, network, and identity and maps them to the MITRE ATT&CK framework, so that phishing leading to RMM abuse leading to lateral movement can be recognized as one intrusion. Sekoia's discovery of the group's move from Atera to a custom implant is an example of turning first-hand intelligence into detection that keeps up as an actor changes its tools.

The practical takeaway for defenders is that an actor like MuddyWater is caught by understanding behavior and context, not by matching known-bad files. The question is not only whether a file is malicious, but whether this remote-management tool, this script, this login belongs here. That judgment depends on visibility across the whole environment, read together against current intelligence on how the group operates. As a European vendor with a data-sovereignty posture, Sekoia is well placed to support the government and critical-infrastructure organizations that MuddyWater most often targets.