Also known as: TEMP.Zagros, Static Kitten, ATK51, G0069, Boggy Serpens, TA450, Earth Vetala, Seedworm, Mango Sandstorm, MERCURY, COBALT ULSTER
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database