What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. On January 12, 2022, U.S. Cyber Command’s Cyber National Mission Force (CNMF) publicly said MuddyWater was conducting Iranian intelligence activities and was “a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).” A joint U.S.-UK advisory followed on February 24, describing MuddyWater as Iranian government-sponsored and providing further context on its reported operations and defenses.

What USCYBERCOM said about MuddyWater

In its January 12, 2022 release, U.S. Cyber Command CNMF stated: “MuddyWater is a subordinate element within the Iranian Ministry of Intelligence and Security (MOIS).” The announcement attributed the statement institutionally to CNMF Public Affairs; it did not name an individual speaker.

This is an official U.S. government attribution. The public release establishes what CNMF said, but does not provide a detailed public evidentiary record from which readers can independently reconstruct the intelligence basis. Read the January 12, 2022 USCYBERCOM announcement for the original wording.

What the later joint advisory added

On February 24, 2022, the FBI, CISA, USCYBERCOM CNMF, and the UK National Cyber Security Centre issued a joint advisory describing MuddyWater as a group of Iranian government-sponsored advanced persistent threat actors. The agencies said the group had conducted broad cyber campaigns in support of MOIS objectives since approximately 2018. That is an approximate timeline reported in the advisory, not a measured statistic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The advisory also listed the names Earth Vetala, MERCURY, Static Kitten, Seedworm, and TEMP.Zagros for the group. Naming conventions can vary among security organizations, so the aliases help readers connect reporting that may use different labels.

The agencies reported cyber espionage and other malicious operations against public- and private-sector organizations, including telecommunications, defense, local government, and oil and natural gas. Reported activity spanned Asia, Africa, Europe, and North America. These are the advisory’s descriptions of activity; they do not establish a victim count or success rate.

Reported tactics and malware

The February advisory described methods including spearphishing, exploitation of publicly reported vulnerabilities, use of open-source tools, DLL sideloading, and obfuscated PowerShell. It listed these observed malware families and tools:

  • PowGoop
  • Small Sieve
  • Canopy, also called Starwhale
  • Mori
  • POWERSTATS

These are observations documented in a 2022 advisory, not confirmation that every tool remains in use today. The joint advisory and its technical details are the relevant source for the agencies’ reported tactics and malware.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the two 2022 announcements differ

Date Issuing body What it did
January 12, 2022 U.S. Cyber Command CNMF Publicly linked MuddyWater to Iranian intelligence activities and MOIS.
February 24, 2022 FBI, CISA, USCYBERCOM CNMF, and UK NCSC Characterized MuddyWater as Iranian government-sponsored and provided reported operational context and defensive recommendations.

The headline refers to the January 2022 attribution, not a new announcement in 2026.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations can do with the advisory

The agencies’ 2022 recommendations are defensive measures, not a complete security program or a guarantee of protection. Organizations can use the advisory to inform their own security processes:

  • Search systems and networks for the indicators of compromise listed in the advisory.
  • Use antivirus software and keep it updated.
  • Patch systems, prioritizing known exploited vulnerabilities.
  • Train users to recognize and report phishing attempts.
  • Use multifactor authentication (MFA) for accounts. A FIDO2 security key is one possible physical way to support MFA; the agencies did not endorse a particular brand or model.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.