MuddyWater is an Iranian-based threat group that has primarily targeted Middle Eastern countries, but has also targeted European and North American countries. This group has primarily targeted victims in the telecommunications, government IT services, and oil industries. This group’s activity was previously linked to FIN7, but the group is suspected to be a distinct group, possibly motivated by espionage.

Other names for this threat

Seedworm, Static Kittens, TEMP.Zagros

This is a collection of rules based on the presence of indicators of compromise publicly reported as associated with this malicious actor.