Validin will be at Black Hat 2026, Booth #6200 — schedule time to meet with us for an enterprise demo or an online meeting

MuddyWater

Aliases: Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450 • MuddyWater is an Iranian state-sponsored espionage group known for targeting government and private sector organizations globally. They have been active since at least 2017.
Profile
Malicious
Category
Threat Actor Group
Threat Type
IR
Country
muddywater
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
Last Updated
Summary
Indicator Activity
Loading activity...
No indicators recorded yet.
Description

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across various sectors, including telecommunications, local government, defense, and oil and natural gas, in the Middle East, Asia, Africa, Europe, and North America.

Aliases (7)
Earth Vetala
Alias
MERCURY
Alias
Static Kitten
Alias
Seedworm
Alias
TEMP.Zagros
Alias
Mango Sandstorm
Alias
TA450
Alias
Targets (9)
Government
Target
Telecommunications
Target
Defense
Target
Oil & gas
Target
Middle East
Target
Asia
Target
Africa
Target
Europe
Target
North America
Target
External Sources
Description References (1)
Reference