MuddyWater Exposed: Inside an Iranian APT operation
Essential information
- Published
- 05/03/2026 15:18
- Modified
- 05/03/2026 15:50
- Tags
- 2026-03-05 CVE-2022-42475 CVE-2024-23113 CVE-2024-55591 CVE-2025-34291 CVE-2025-52691 CVE-2025-54068 CVE-2025-55182 CVE-2025-5777 CVE-2025-68613 CVE-2025-9316 CVE-2026-1281 CVE-2026-1731 arenac2 command and control cyber espionage exfiltration geopolitical conflict iranian apt keyc2 mois persianc2 reconnaissance tsundere botnet vulnerability exploitation
- Related entities
- 13 vulnerabilities (cve), 14 observables, 1 intrusion sets (apt), 4 malware, 12 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (13)
CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker …
- Attack vector
- PHYSICAL
- Published
- 12/06/2024
- Modified
- 05/03/2026
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files …
- Attack vector
- NETWORK
- Published
- 29/12/2025
- Modified
- 05/03/2026
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or …
- Attack vector
- Network
- Published
- 09/10/2024
- Modified
- 05/03/2026
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
- Attack vector
- NETWORK
- Published
- 29/01/2026
- Modified
- 27/03/2026
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary …
- Attack vector
- Network
- Published
- 13/12/2022
- Modified
- 20/12/2025
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive …
- Attack vector
- Network
- Complexity
- Low
- EPSS
- 0.0246 (P84.8%)
- Published
- 06/12/2025
- Modified
- 23/05/2026
N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.
- Published
- 05/03/2026
- Modified
- 05/03/2026
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical …
- Attack vector
- Network
- Published
- 20/12/2025
- Modified
- 12/03/2026
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 17/07/2025
- Modified
- 27/03/2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through …
- Attack vector
- Network
- Published
- 14/01/2025
- Modified
- 27/05/2026
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread …
- Attack vector
- Network
- Published
- 10/07/2025
- Modified
- 21/12/2025
Observables (14)
-
209.74.87.100 -
157.20.182.49 -
209.74.87.67 -
194.11.246.101 -
185.236.25.119 -
84.110.105.214 -
193.17.183.126 -
162.0.230.185 -
http://157.20.182.49:10443/success -
www.xt24.com -
http://194.11.246.101:1338 -
bedb882c6e2cf896e14ecf12c90aaa6638f780017d1b8687a40b4a81956e230f
Intrusion sets (APT) (1)
-
The MITRE Corporation Confidence 100
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (4)
-
Family
-
Family
-
Family
-
Family
Others (12)
-
United Arab Emirates
-
Egypt
-
Israel
-
Jordan
-
United States of America
-
Portugal
-
Finance
-
Health
-
Transport
-
Government and administrations
-
Defense
-
Technologies