Skip to main content

Pentagon says Iran is behind MuddyWater hacking group

Iranian intelligence is behind a group of cyber-attackers that have targeted private and government organizations across the Middle East.

Nakasone cyber
Paul Nakasone, commander of the U.S. Cyber Command, speaks during a House Intelligence Committee hearing on April 15, 2021 in Washington, D.C. The U.S. and its allies will face "a diverse array of threats" in the coming year, with aggression by Russia, China and Iran. — Al Drago-Pool/Getty Images

The United States military identified Iranian intelligence as being behind a group of hackers widely known as MuddyWater on Wednesday, confirming previous reports by private cybersecurity groups.

MuddyWater has reportedly attacked both government and private enterprise networks in the Middle East, but has also targeted organizations in the United States.

The group, also believed to be known as Seedworm, Static Kitten, TEMP.Zagros and MERCURY, has reportedly targeted government, telecom and NGO organizations in Israel, Saudi Arabia, Turkey, Jordan, Iraq, the United Arab Emirates, Pakistan and Georgia as far back as 2017.

In September 2020, MuddyWater launched a broad ransomware campaign known as Operation Quick Sand targeting prominent Israeli organizations. The attack was identified by Israeli firm Clear Sky Cyber Security, and carried out in part via emailed PDF and Excel files.

SUBSCRIBER EXCLUSIVE

Continue reading this exclusive analysis

Original reporting and analysis unavailable elsewhere. Subscribe to AL-MONITOR to read this story and access everything we publish