Iran's APTs and the U.S. Enterprise in 2026: MuddyWater
Post 2 of 5 - How a MOIS-subordinated espionage group with a reputation for moderate technical sophistication came to target U.S. banking, a major U.S. airport, and, according to public reporting, a Jerusalem CCTV server in the days before Iranian missile strikes.
Published July 22, 2026

In early February 2026, MuddyWater operators reportedly deployed a previously undocumented backdoor named Dindoor. Deployment intensified through March, coinciding with what public reporting describes as heightened geopolitical tensions in the Middle East. The named targets included U.S. banking and finance entities, a major U.S. airport, and the Israeli operations of a U.S.-based software company. Exfiltration ran through Rclone to Wasabi cloud storage, legitimate tooling, and routine traffic.
If you read Post 1 of this series, that opening paragraph is familiar. This post explains what sits behind it: how MuddyWater got from spear-phishing Turkish government departments in 2017 to operating at military tempo against U.S. enterprises in 2026, and what its current tradecraft means for the Global 1000 security teams that have not yet adjusted their threat models.
» Start with KELA and stay ahead in identifying advanced threat actors and operations
Who is MuddyWater?
The group has matured from a regionally focused espionage actor into a global intelligence capability with selective integration of disruptive and operational tradecraft. It is not consistently sophisticated by top-tier APT standards; its strength is iterative development, operational consistency, and effective use of legitimate tools to blend with normal enterprise activity.
Targeting is sector-broad and geography-deep, with a clear preference for entities operating in or connected to the Middle East.
The group's known targets include:
- Government
- Telecommunications
- IT
- Banking and finance
- Critical infrastructure, including airports and aviation
- Multinational technology companies
U.S. enterprise victims have been named in three of the group's 2025–2026 campaigns:
- Dindoor backdoor deployments (February–March 2026): Targeted U.S. banking, a major U.S. airport, and the Israeli operations of a U.S.-based software company.
- Operation IconCat (late 2025–early 2026): Targeted Israeli managed service providers (MSPs) and defense-adjacent software companies.
- Jerusalem CCTV correlation (June 2025): If accurate, this marks MuddyWater's transition from pure espionage toward intelligence support for kinetic operations.
MuddyWater at a Glance
- Aliases: Mercury, Static Kitten, Mango Sandstorm, Seedworm
- Operates From: Iran
- Sponsor / Backing: Iranian Ministry of Intelligence and Security (MOIS)
- Active Since: At least 2017
- Ideology / Motivation: State-aligned cyber espionage in support of Iranian national security and regional priorities, with selective integration of disruptive and operational tradecraft.
Typical Victims
- Government
- Telecommunications
- IT
- Banking and finance
- Aviation
- Multinational technology companies
Primary focus is the Middle East and North Africa (MENA), with documented victims in the United States, Europe, and Africa.
Signature Tactics, Techniques, and Procedures (TTPs)
- Spear-phishing with weaponized Microsoft Office documents
- Abuse of legitimate remote management tools (AnyDesk, ScreenConnect, RemoteUtilities)
- Telegram-based command and control (C2)
- Living-off-the-land binaries (LOLBins)
- Rclone exfiltration to commercial cloud services
- In-memory malware loading
- Hacktivist persona masquerading (DarkBit)
Notable Activity (2025–2026)
- Dindoor backdoor targeting U.S. banking and a major U.S. airport
- Operation Olalampo
- Operation IconCat
- Reported Jerusalem CCTV correlation
For a Global 1000 enterprise, the actionable risk surface is large. MuddyWater's extensive use of legitimate Remote Monitoring and Management tools (AnyDesk, ScreenConnect, RemoteUtilities), legitimate file-sharing platforms (Egnyte, OneHub, Mega), Telegram-based command-and-control, and exfiltration via Rclone to commercial cloud storage means traditional perimeter and signature-based detection are unlikely to surface intrusions on their own.
The group's operational tempo through Operation Epic Fury in early 2026 indicates no near-term slowdown in tooling refresh or victim selection. MuddyWater is the Iranian APT whose victimology most directly names U.S. enterprises in the current operating quarter, and the group whose tradecraft is most calibrated against living inside an enterprise undetected.
MuddyWater Campaign Arc
MuddyWater's history is a study in iteration rather than reinvention: the same operational core (spear-phishing, legitimate tooling, blending into normal traffic) refined campaign after campaign as defenders caught up.
Regional Espionage Origins (2017–2019)
MuddyWater surfaced in 2017 with spear-phishing campaigns against government departments in Turkey and the wider region, establishing the pattern that still defines it: weaponised Office documents, contextual lures, and a preference for blending in over technical spectacle.
It earned a reputation as a capable but not top-tier espionage actor, valued by the regime for consistency and reach rather than for zero-days.
Maturation and the DarkBit turn (2020–2023)
Through the early 2020s the group scaled from a regional operation into a broader intelligence capability, leaning on legitimate remote-management tools (AnyDesk, ScreenConnect, RemoteUtilities) and custom command-and-control frameworks such as the Go-based MuddyC2Go, which replaced its earlier PowerShell-based C2.
The turn came in 2023, when operators ran the Technion University attack behind the "DarkBit" hacktivist persona: an early sign that MuddyWater would fold disruptive, identity-obscuring operations into what had been a pure espionage profile.
Back to Custom Tooling (2024)
As endpoint detection of RMM abuse improved, MuddyWater adapted rather than retreated. The 2024 BugSleep campaign (also tracked as MuddyRot) was a deliberate move back to custom-coded backdoors, a compact C/C++ implant built to do quietly what borrowed tools no longer could. In parallel, telecommunications campaigns across Egypt, Sudan, and Tanzania pushed the group's footprint well beyond its MENA core.
By the end of 2024 the pieces were in place for the military-tempo year that followed: an adaptive development function, a demonstrated taste for disruption, and a genuinely global reach.
Latest Campaigns
Operation IconCat: The Hybrid Pivot
Operation IconCat, observed in late 2025 and continuing into early 2026, is the campaign that most clearly marks MuddyWater's shift from pure espionage toward a hybrid model combining surgical reconnaissance with destructive capabilities.
The targets were primarily Israeli: Managed Service Providers and defense-adjacent software companies. The supply-chain implication extends beyond Israel. MSPs by definition concentrate downstream access. Defense-adjacent software vendors sit upstream of multinational defense and government customers.
Several of those downstream customers are U.S. enterprises.
Initial access was achieved through spear-phishing (T1566.001), with recipients directed to download a purported "security scanner" via Dropbox links or malicious Word and PDF attachments. The lures were enhanced with high-resolution icons mimicking well-known cybersecurity vendors, a credibility boost specifically designed to defeat the trained-user check.
The headline implant was RUSTRIC (also tracked as RustyWater), a Rust-based reconnaissance implant hardcoded with a list of 28 security products. On execution, RUSTRIC profiles the system for specific EDR and antivirus solutions before initiating C2 communications. Persistence ran through Windows Registry run keys (T1547.001), masquerading as a legitimate system "Update Manager."
PYTRIC: Where IconCat departed from MuddyWater's established pattern was the secondary payload. Alongside RUSTRIC, the group deployed PYTRIC, destructive tooling with full system wiping and local backup deletion capabilities (T1485, T1561). To evade network defenses, PYTRIC's C2 ran through Telegram bots (T1102) rather than dedicated infrastructure, blending malicious traffic with legitimate encrypted messaging.
Code-overlap analysis adds analytical weight.
Researchers identified PDB strings containing the username "Jacob" in RUSTRIC samples, the same identifier later observed in the CHAR backdoor used in Operation Olalampo.
The overlap suggests that IconCat and Olalampo are not isolated campaigns but components of a coordinated, well-resourced development pipeline in which operators reuse:
- Code
- Tooling
- Development environments
This accelerates the deployment of Rust-based malware families. This is not the operational profile of a moderately sophisticated group. It is the profile of a group with a sustained engineering function.
The Jerusalem CCTV Correlation
Of the activity documented in this post, the June 2025 Jerusalem CCTV incident carries the highest analytical implications and the most carefully hedged language.
What public reporting says: in the days preceding Iranian missile strikes on Jerusalem in mid-June 2025, MuddyWater-linked infrastructure correlated with access to a compromised CCTV server in the city. The threat actor reportedly gained access to live CCTV streams, providing real-time visual intelligence of potential targets. The temporal alignment with the missile strikes is the diagnostic detail.
If accurate, the activity represents a meaningful evolution in MuddyWater's operational role: an espionage group with a 2017-era reputation for moderate sophistication providing intelligence support to kinetic military operations in near real-time. The implication is not limited to MuddyWater. It is the operational template, cyber access feeding kinetic targeting at military tempo, that the rest of the Iranian APT ecosystem can observe and replicate.
For U.S. enterprises, the case has implications. The continental U.S. is not the operational theatre for Iranian missile strikes. But the precedent, that a MOIS-subordinated cyber group can be tasked to deliver real-time visual intelligence in support of kinetic operations, sets the upper bound on what the group is capable of being directed to do. Threat modelling against that capability is different from threat modelling against an espionage-only profile.
» Understand how threat actors breach and exploit your data
Latest Campaigns
Dindoor Used to Target U.S. in Early 2026
The Dindoor backdoor is the operational headline for MuddyWater's U.S.-relevant 2026 activity. It is also a useful case study in why "we don't operate in the Middle East" no longer functions as a threat-model exemption.
Dindoor itself is an implementation choice worth pausing on. Unlike conventional MuddyWater backdoors written in C++ or Python, it leverages Deno, a runtime for JavaScript and TypeScript. The technical implication is meaningful for defenders: Deno-based execution enables complex post-compromise logic in an environment that most enterprise security controls were not built to inspect. Most endpoint detection, threat-hunt queries, and SIEM rules are calibrated against PowerShell, Office macros, .NET, native PE binaries, or, at the more capable end, Python tooling. JavaScript runtime execution falls into a gap, particularly when the parent process is something benign-looking.
The backdoor provides persistent access, supports arbitrary command execution, file management, and lateral movement (T1021). In the documented intrusions, MuddyWater paired Dindoor with Rclone (T1567.002) to exfiltrate data to Wasabi cloud storage, a deliberate legitimate-tools choice that blends with normal SaaS traffic and defeats DLP rules built around specific cloud-storage destinations.
In parallel, the group deployed Fakeset, also tracked as Castle Loader, a Python-based persistence mechanism. Fakeset establishes Windows Registry run keys and startup folder entries (T1547.001), maintaining long-term access through system reboots.
One detail in the Dindoor target set carries broader implications. The U.S.-based software company in the campaign was reached through its Israeli operations, but the access, and the post-compromise tooling, sat on U.S.-facing infrastructure. Enterprises whose threat models treat Israel-region operations as "out of scope" for US-side defense are mismatched against this access path.
Operation Olalampo and the AI signal
Operation Olalampo is the campaign around which MuddyWater's late-2025 / early-2026 tooling refresh is built. First observed on January 26, 2026, the operation targeted multiple organizations and individuals primarily across the MENA region, in a manner public reporting describes as consistent with broader regional geopolitical tensions.
Olalampo introduces four malware families, several of them new additions to MuddyWater's toolkit:
- GhostBackDoor is the primary post-access implant. It supports remote access, file operations, and privilege-aware behavior adaptation. The implant modifies its own behavior based on host privileges available, a modular design intended to maximize utility across heterogeneous victims, from low-privilege workstations to domain-joined hosts with elevated access.
- CHAR, also used in Operation IconCat, is the most technically significant family in the campaign. Rust-based, deployed in later stages of compromise, reserved for high-value targets where sustained access is the priority. C2 runs through a Telegram bot named Olalampo; operators issue commands through PowerShell or the Windows command interface (T1059.001, T1059.003).
Post-compromise activity in Olalampo emphasizes credential theft and long-term persistence. Using the CHAR backdoor, operators reportedly created tunnels within victim networks and deployed the Kalim malware family alongside utilities designed to extract browser data and saved credentials.
» Learn about the difference between leaked credentials and compromised accounts
The AI Signal
Researchers analyzing Operation Olalampo identified stylistic artifacts in the malware binaries consistent with LLM-generated code conventions, including emoji-based status reporting using ✅ and ❌ markers in the command dispatcher.
This pattern is atypical in conventional malware development. Google Cloud Threat Intelligence has separately reported MuddyWater's use of Gemini to support custom malware research and development. The evidence is suggestive rather than dispositive, we hedge the language accordingly. But the implication for defenders is concrete: the cost and time required to produce new tooling falls, the operational tempo rises, and signature-based detections decay faster than they did against MuddyWater's 2022-era development pipeline.
» Learn more: Reasons you need cyber threat intelligence
TTPs: How MuddyWater Operates
Tradecraft summary
The group's tradecraft sits in five tactical buckets. Full MITRE ATT&CK mapping and runnable hunt queries are in the appendix and the companion GitHub repository linked at the close of this post.
Initial Access
Spear-phishing (T1566.001, T1566.002) remains the primary vector, with weaponised Office documents (Word, Excel, PDF) carrying embedded macros (T1204.002) or malicious links. Lures are contextually tailored to regional or sector themes and frequently impersonate trusted entities. The group has expanded into compromised corporate email accounts and legitimate file-sharing platforms, Egnyte, OneHub, Mega (T1199, T1078.004), to bypass perimeter email controls.
Execution, Evasion, and Persistence
Macro-enabled document execution flows into PowerShell payload delivery (T1059.001) and in-memory loading of secondary payloads (T1620). Living-off-the-land binaries (T1218) and legitimate tools — PowerShell, AnyDesk (T1219), ScreenConnect, RemoteUtilities — are core to the evasion strategy. Environment-awareness checks against VMs and EDR/AV products (T1497, T1518.001) are routine. Persistence runs through Windows Registry run keys (T1547.001), custom loaders (Fakeset/Castle Loader), and reinfection capabilities embedded in implants such as GhostBackDoor. The DarkBit hacktivist persona (used in the 2023 Technion University attack) represents attribution obfuscation as a tradecraft technique (T1036.004).
Command and Control
MuddyWater uses a mix of custom frameworks and legitimate platform abuse. Custom: MuddyC2Go (Go-based, replacing earlier PowerShell-based C2), CHAR. HTTP/S-based loaders: HTTP_VIP. Legitimate platform abuse: Telegram bot C2 for PYTRIC and the Olalampo dispatcher (T1102). The legitimate-platform pattern reduces reliance on suspicious domains and effectively replaces traditional domain generation algorithm techniques with trusted-infrastructure abuse, a meaningful shift for any detection programme built around C2 domain reputation.
Credential Access and Collection
Credential dumping (T1003), browser data extraction including saved passwords and session cookies (T1555.003), clipboard capture (T1115). The 2024 BugSleep/MuddyRot campaign — a custom C/C++ backdoor — represented MuddyWater's deliberate move back toward custom-coded credential tooling as EDR detection of RMM abuse improved.
Exfiltration
Exfiltration via legitimate tools — most consistently Rclone to commercial cloud storage such as Wasabi (T1567.002) — is the documented Dindoor-campaign pattern and is consistent with the broader living-off-the-land approach.
» Learn how you can prepare your organization for the future of cybercrime
Sectors and Victimology
MuddyWater's victimology aligns consistently with Iranian strategic and geopolitical priorities. Targeting concentrates on entities providing intelligence value, operational access, or potential for strategic disruption.
Geographically, activity has been concentrated in the Middle East but is documented across Europe, Asia, and North America, particularly organizations with direct or indirect links to the region.
Recent campaigns (2023–2026) show clear prioritization of Israeli and broader MENA targets, including local government, telecommunications, IT, manufacturing, civil aviation, tourism, healthcare, and SMEs. The 2024 telecommunications campaigns in Egypt, Sudan, and Tanzania signal an additional layer of strategic interest in Africa's communications infrastructure, a footprint that connects upstream to multinational telecom operators with European and U.S. shareholders.
Three Takeaways for the U.S. Enterprise
1. Perimeter Detection Is No Longer the Primary Control Surface
Rclone, AnyDesk, ScreenConnect, RemoteUtilities, and Telegram all generate traffic that defaults to benign in most enterprise contexts.
Detection has to shift to behavioral and identity-aware patterns, including:
- Anomalous Rclone destinations
- AnyDesk install events on workstations without a documented RMM footprint
- Telegram API traffic from server-class hosts
- Registry run-key additions named "Update Manager" or similar legitimate-sounding strings
- Deno or JavaScript runtime execution on hosts where neither is a sanctioned development tool
2. Supply Chain Is the Threat Model, Not an Addendum to It
The Dindoor campaign's hit on the Israeli operations of a U.S.-based software company is the precedent. Operation IconCat's targeting of Israeli MSPs and defense-adjacent software extends it.
The actionable question is not "Do I operate there?" It is: "Where does my Israeli-region or broader MENA exposure begin?"
That question should extend across:
- Vendors
- Partners
- Individual contributors
- Recently acquired subsidiaries
3. The Military-Tempo Evidence Raises the Floor on What to Plan Against
Whether or not the Jerusalem CCTV linkage is verified, MuddyWater's operational tempo through Operation Epic Fury suggests the group will continue to refresh tooling against geopolitical triggers rather than calendar cycles.
Threat models built against 2022-era MuddyWater are out of date.
The 2026 threat model is a group with:
- A sustained engineering function
- A demonstrated willingness to integrate destructive payloads alongside espionage tooling
- A documented operational tempo that aligns to kinetic events
Coming Next
The next post in this series, APT42: The IRGC's Long-Game Espionage Apparatus, examines the IRGC-IO group whose tradecraft turns the workforce edge into the attack surface.
It opens with the UNK_SmudgedSerpent campaign impersonating named U.S. foreign-policy experts and walks through SpearSpecter, TAMECAT, and the cloud-resident persistence patterns that make APT42 the hardest of the four groups to dislodge once it is inside.




