Bringing cybersecurity globally to critical and complex key activities
Alias: MERCURY, MobhaM, MuddyWater, NTSTATS, POWERSTATS, Seedworm, Static Kitten, TEMP.Zagros
ATK51 (aka: MuddyWater) is an Iranian threat group. Attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.
REFERENCES