BlackShadow
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
MuddyWater is an Iranian threat actor that has been publicly linked to the Islamic Revolutionary Guard Corps (IRGC) in multiple security reports. No other aliases are mentioned in the source material, and the group is consistently referenced by this name in the analyzed reporting. The association with a state‑linked organization provides the primary basis for attributing the activity to a national‑level sponsor rather than a purely criminal enterprise.
The actor’s observed focus has been on Israeli interests, with specific public warnings from Israeli cybersecurity firms Profero and ClearSky indicating that MuddyWater was planning disruptive or destructive operations against targets in Israel during a September timeframe. This strategic aim is described as intending to cause damage or disruption rather than purely financial gain, reflecting a motive aligned with state‑oriented objectives. The targeting appears to be geographically concentrated on entities within Israel, although the reporting does not detail specific sectors beyond the general reference to national interests.
Regarding tactics, MuddyWater has been observed using phishing emails as an initial access vector and exploiting the CVE‑2020‑0688 vulnerability in Microsoft Exchange to gain a foothold on victim networks. After gaining access, the group deploys a fraudulent Google Updater tool named PowGoop, which subsequently delivers the Thanos ransomware—also referred to as Hakbit—as the payload. The Thanos ransomware itself is noted to be offered as a ransomware‑as‑a‑service on Russian‑speaking underground forums, where the developers receive a share of any ransom payments, indicating a financial component to the malware’s distribution model even if the immediate operational goal appears disruptive.
Attribution to the IRGC is drawn from the explicit linkage made in the cited threat intelligence reports, establishing a clear state nexus for the group’s activities. A representative operation highlighted in the sources is the disclosed planning of destructive actions against Israeli targets in September 2020, which Profero and ClearSky noted they could impede but anticipated further attempts. This episode illustrates the group’s capacity to combine social engineering, software vulnerability exploitation, and ransomware deployment in pursuit of its objectives. No additional speculative details about the group’s size, internal structure, or financial motives are included beyond what is directly stated in the provided material.
Incidents
Attributed incidents are available to members.
5 incidents