What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Yes. On January 12, 2022, U.S. Cyber Command’s Cyber National Mission Force (CNMF) publicly said MuddyWater was conducting Iranian intelligence activities and was “a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).” A joint U.S.-UK advisory followed on February 24, describing MuddyWater as Iranian government-sponsored and providing further context on its reported operations and defenses.
What USCYBERCOM said about MuddyWater
In its January 12, 2022 release, U.S. Cyber Command CNMF stated: “MuddyWater is a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).” The announcement attributed the statement institutionally to CNMF Public Affairs; it did not name an individual speaker.
This is an official U.S. government attribution. The public release establishes what CNMF said, but does not provide a detailed public evidentiary record from which readers can independently reconstruct the intelligence basis. Read the January 12, 2022 USCYBERCOM announcement for the original wording.
What the later joint advisory added
On February 24, 2022, the FBI, CISA, USCYBERCOM CNMF, and the UK National Cyber Security Centre issued a joint advisory describing MuddyWater as a group of Iranian government-sponsored advanced persistent threat actors. The agencies said the group had conducted broad cyber campaigns in support of MOIS objectives since approximately 2018. That is an approximate timeline reported in the advisory, not a measured statistic.
The advisory also listed the names Earth Vetala, MERCURY, Static Kitten, Seedworm, and TEMP.Zagros for the group. Naming conventions can vary among security organizations, so the aliases help readers connect reporting that may use different labels.
The agencies reported cyber espionage and other malicious operations against public- and private-sector organizations, including telecommunications, defense, local government, and oil and natural gas. Reported activity spanned Asia, Africa, Europe, and North America. These are the advisory’s descriptions of activity; they do not establish a victim count or success rate.
#1 Best Overall
Reported tactics and malware
The February advisory described methods including spearphishing, exploitation of publicly reported vulnerabilities, use of open-source tools, DLL sideloading, and obfuscated PowerShell. It listed these observed malware families and tools:
- PowGoop
- Small Sieve
- Canopy, also called Starwhale
- Mori
- POWERSTATS
These are observations documented in a 2022 advisory, not confirmation that every tool remains in use today. The joint advisory and its technical details are the relevant source for the agencies’ reported tactics and malware.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →How the two 2022 announcements differ
| Date | Issuing body | What it did |
|---|---|---|
| January 12, 2022 | U.S. Cyber Command CNMF | Publicly linked MuddyWater to Iranian intelligence activities and MOIS. |
| February 24, 2022 | FBI, CISA, USCYBERCOM CNMF, and UK NCSC | Characterized MuddyWater as Iranian government-sponsored and provided reported operational context and defensive recommendations. |
The headline refers to the January 2022 attribution, not a new announcement in 2026.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What organizations can do with the advisory
The agencies’ 2022 recommendations are defensive measures, not a complete security program or a guarantee of protection. Organizations can use the advisory to inform their own security processes:
Quick Recap
Best Value
Rank #4
Rank #3
- Search systems and networks for the indicators of compromise listed in the advisory.
- Use antivirus software and keep it updated.
- Patch systems, prioritizing known exploited vulnerabilities.
- Train users to recognize and report phishing attempts.
- Use multifactor authentication (MFA) for accounts. A FIDO2 security key is one possible physical way to support MFA; the agencies did not endorse a particular brand or model.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

