US Cyber Command (USCYBERCOM) has officially linked the Iranian-backed MuddyWater hacking group to Iran’s Ministry of Intelligence and Security (MOIS).
MOIS is the Iran government’s leading intelligence agency, tasked with coordinating the country’s intelligence and counterintelligence, as well as covert actions supporting the Islamic regime’s goals beyond Iran’s borders.
USCYBERCOM stated that these actors, known as MuddyWater are part of groups conducting Iranian intelligence activities, and was found using a variety of techniques to maintain access to victim networks.
The cyber-espionage group has primarily targeted Middle Eastern nations, and has also targeted European and North American nations. It is a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).”
MuddyWater aka SeedWorm and TEMP.Zagros was first spotted in 2017 and is continuously upgrading its arsenal.
The Iranian-sponsored APT group is highly active, and it targets the telecommunications, government (IT services), and oil industry sectors.
The hacking group was also found expanding their attacks to government and defense entities in Central and Southwest Asia, and numerous privately-held and public organizations from North America, Europe, and Asia.
USCYBERCOM’s Cyber National Mission Force (CNMF) in collaboration with the FBI, has also shared multiple malware samples used by the Iranian hacking group’s operators in espionage and malicious activity.
The samples include multiple variants of PowGoop, a DLL loader designed to decrypt and run a PowerShell-based malware downloader.
MuddyWater has been seen using a variety of techniques to maintain access to victim networks. These include side-loading DLLs to trick legitimate programs into running malware and obfuscating PowerShell scripts to hide command and control functions.













Comments