Full Report
Group-IB analysts discovered the new MuddyWater infrastructure while researching the pro-state group’s use of the legitimate SimpleHelp tool.
Analysis Summary
# Threat Actor: MuddyWater
## Attribution & Identity
* **Name:** MuddyWater
* **Known Aliases:** Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros.
* **Attribution:** Legally attributed by the US Cyber Command and the FBI to the **Iranian Ministry of Intelligence and Security (MOIS)**.
* **Associated Groups:** Often linked to other Iranian state-sponsored clusters; described as a pro-state actor serving Iranian national interests.
## Activity Summary
Group-IB researchers identified a shift in MuddyWater's infrastructure, moving toward the exploitation of legitimate remote management software to maintain persistence and control over target environments. The core of the recent activity involves the deployment of the **SimpleHelp** tool, which the group uses to bypass security controls that might otherwise flag custom-built backdoors. By using a legitimate tool, the actor blends in with standard administrative traffic.
## Tactics, Techniques & Procedures
* **Living off the Land (LotL):** Utilizing legitimate tools like SimpleHelp for remote access and persistence.
* **Phishing:** Historical and ongoing use of social engineering to deliver initial payloads.
* **Lateral Movement:** Using compromised credentials and remote management tools to traverse the network.
* **Command and Control (C2):** Leveraging legitimate software infrastructure to mask malicious traffic.
* **Defense Evasion:** Using ETag tracking and legitimate software to avoid signature-based detection.
* **Persistence:** Installing SimpleHelp as a service on victim machines.
## Targeting
* **Sectors:** Historically targets Government, Telecommunications, Oil & Gas, Defense, and critical infrastructure.
* **Geography:** Primarily focused on the Middle East (specifically Israel, Saudi Arabia, UAE, and Turkey), though activities have expanded to Europe, North America, and parts of Asia (Pakistan, India).
* **Victims:** While specific organizations are not named in the snippet, the group targets entities of strategic interest to the Iranian government.
## Tools & Infrastructure
* **Malware/Software:**
* **SimpleHelp:** A legitimate remote support tool used for persistent access.
* **Ligolo:** A tunneling tool often used by this actor for communication.
* **Infrastructure (Defanged):**
* **ETags:** `2aa6-5c939a3a79153`, `2aa6-5b27e6e58988b`, `2aa6-5c939a773f7a2`
* **IP Addresses (C2/SimpleHelp Servers):**
* 137.74.131[.]16
* 137.74.131[.]18
* 137.74.131[.]19
* 137.74.131[.]20
* 137.74.131[.]22
* 137.74.131[.]24
* 137.74.131[.]30
* 141.95.177[.]129
* 141.95.177[.]130
* 141.95.177[.]131
* 141.95.177[.]132
* 141.95.177[.]133
* 141.95.177[.]134
* 141.95.177[.]135
* 141.95.177[.]142
* 141.95.177[.]143
* 149.202.242[.]80
* 149.202.242[.]84
* 149.202.242[.]85
* 149.202.242[.]86
* 149.202.242[.]87
* 151.80.172[.]146
* 151.80.172[.]147
* 151.80.172[.]149
* 164.132.237[.]64
* 164.132.237[.]65
* 164.132.237[.]66
* 164.132.237[.]70
* 164.132.237[.]71
* 164.132.237[.]74
* 164.132.237[.]75
* 164.132.237[.]76
* 164.132.237[.]78
* 178.32.30[.]0
* 178.32.30[.]1
* 178.32.30[.]2
* 178.32.30[.]3
* 91.121.240[.]96 through 111 (Subnet)
* 91.134.169[.]137
* 91.134.169[.]139
* 51.255.19[.]183
* 51.254.25[.]36
## Implications
MuddyWater’s shift toward legitimate remote management tools represents a significant hurdle for traditional EDR and antivirus solutions. By utilizing "authorized" software, they minimize the footprint of their attacks. Their continued focus on Middle Eastern targets suggests they remain a primary tool for Iranian intelligence gathering and regional influence operations.
## Mitigations
* **Application Whitelisting:** Audit and restrict the use of remote management tools (like SimpleHelp, AnyDesk, ScreenConnect) to only authorized personnel.
* **Network Monitoring:** Monitor for unusual outbound connections to the specific IP addresses and subnets associated with this infrastructure.
* **Threat Intelligence:** Integrate real-time TI feeds to detect known C2 IP addresses and ETags at the edge.
* **Behavioral Analysis:** Configure security tools to alert on the installation of remote management software as a service by non-administrative users.
* **Credential Protection:** Implement MFA to prevent lateral movement even if the actor gains initial access.