Adversary-emulation profile for MuddyWater (G0069 / Mercury / Mango Sandstorm / Static Kitten / TEMP.Zagros / Seedworm), Iran's MOIS cyber-espionage actor.
59
68%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/muddywater/SKILL.mdMuddyWater (MITRE ATT&CK G0069) is a cyber-espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017. The group has targeted government, telecommunications, defense, oil & gas, and IT organizations across the Middle East, Central/South Asia, Africa, Europe, and North America. MuddyWater is characterized by heavy reliance on PowerShell-based backdoors (POWERSTATS and its successors), evolving custom C2 frameworks (PhonyC2 → MuddyC2Go), abuse of legitimate Remote Monitoring and Management (RMM) tools (Atera, ScreenConnect, SimpleHelp), spearphishing with macro-laden documents, and a pragmatic blend of custom and open-source post-exploitation tooling. A February 2022 joint U.S./UK advisory (CISA AA22-055A) formally attributed the group to MOIS.
net user /domain).KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding; used by POWERSTATS, Small Sieve, STARWHALE, MuddyViper, RustyWater, and Tsundere Botnet.-WindowStyle Hidden); Koadic and Tsundere Botnet use hidden windows.net user /domain and CrackMapExec for domain account enumeration.%temp% and other directories.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| POWERSTATS | S0223 | PowerShell-based first-stage backdoor / RAT | Custom |
| PowGoop | S1046 | PowerShell/DLL loader and C2 agent | Custom |
| Small Sieve | S1035 | Python-based Telegram Bot API backdoor | Custom |
| STARWHALE / Canopy | S1037 | VBScript-based Windows Script backdoor | Custom |
| Mori | S1047 | DLL backdoor with DNS tunneling C2 | Custom |
| SHARPSTATS | S0450 | .NET-based backdoor | Custom |
| MuddyViper | S9032 | Modular C2 implant (reflective loading) | Custom |
| Fooder | S9033 | Reflective-loading backdoor | Custom |
| LP-Notes | S9036 | Credential harvester with GUI input capture | Custom |
| RustyWater | S9037 | Rust-based implant with anti-debug | Custom |
| Tsundere Botnet | S9034 | JavaScript/PowerShell botnet framework | Custom |
| DCHSpy | S1243 | Android surveillanceware | Custom |
| Out1 | S0594 | Python-based data exfil and email collector | Custom |
| PhonyC2 | (no ATT&CK ID) | Python-based custom C2 framework (2021–2023) | Custom |
| MuddyC2Go | (no ATT&CK ID) | Go-based custom C2 framework (2023–present) | Custom |
| MuddyC3 | (no ATT&CK ID) | Python-based C2 framework (predecessor to PhonyC2) | Custom |
| DarkBeatC2 | (no ATT&CK ID) | Custom C2 framework | Custom |
| Phoenix | (no ATT&CK ID) | Lightweight backdoor implant | Custom |
| Dindoor | (no ATT&CK ID) | Backdoor used in U.S. critical-infra targeting | Custom |
| ConnectWise / ScreenConnect | S0591 | RMM tool (abused for remote access) | Public (RMM) |
| RemoteUtilities | S0592 | RMM tool (abused for remote access) | Public (RMM) |
| SimpleHelp | — | RMM tool (abused for remote access) | Public (RMM) |
| Atera Agent | — | RMM tool (abused for remote access) | Public (RMM) |
| Action1 / Level / PDQ | — | RMM tools (abused for remote access) | Public (RMM) |
| Koadic | S0250 | Post-exploitation framework (COM/JScript) | Public |
| Empire | S0363 | PowerShell/Python post-exploitation framework | Public |
| PowerSploit | S0194 | PowerShell post-exploitation modules | Public |
| CrackMapExec | S0488 | Network/AD enumeration and exploitation | Public |
| Mimikatz | S0002 | Credential dumping and Kerberos attacks | Public |
| LaZagne | S0349 | Multi-platform credential recovery | Public |
| Rclone | S1040 | Cloud sync / exfiltration tool | Public |
| Invoke-Obfuscation | — | PowerShell obfuscation framework | Public |
| go-socks5 | — | SOCKS5 proxy for firewall/NAT bypass | Public |
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never run disruptive (ransomware / "DarkBit"-style) actions outside an explicitly sanctioned, isolated lab.
Map MuddyWater's signature plays to Decepticon's own capabilities:
mshta.exe (T1218.005) and CMSTP.exe (T1218.003) as proxy-execution vectors to launch PowerShell stagers — this is MuddyWater's defining execution pattern.SystemTextEncoding pattern) for PowerShell callbacks; side-load a DLL via a legitimate application for persistence; create scheduled tasks with innocuous names; modify Normal.dotm for Office template persistence.csc.exe; chain proxy-execution binaries (mshta → PowerShell → rundll32); decode Base64 payloads at runtime. Use hidden PowerShell windows (-WindowStyle Hidden) throughout.net user /domain). Lateral-move via pass-the-hash (CrackMapExec/Mimikatz) and exploit Zerologon (CVE-2020-1472) where in scope.makecab.exe or archive utilities; exfiltrate over C2. For the Dindoor/Rclone pattern, use Rclone to sync collected data to cloud storage (Wasabi/S3-compatible). Stage data in %temp% before exfiltration.-WindowStyle Hidden); monitor for PowerShell executing from mshta.exe, CMSTP.exe, or rundll32.exe parent processes.SystemTextEncoding or Windows-Defender-themed keys); audit scheduled task creation; monitor Normal.dotm modification timestamps.makecab.exe archives; alert on large data transfers from staging directories.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.