APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
MuddyWater (aka MuddyWater, STATIC KITTEN) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
MuddyWater
G0069
APT
IR · Iran
AKA
STATIC KITTEN · MERCURY · Seedworm · ATK51 · Earth Vetala · Boggy Serpens · ITG17
CrowdStrike
:
HELIX KITTEN
Mandiant
:
Temp.Zagros
Microsoft
:
Mango Sandstorm
MITRE
:
G0069
Proofpoint
:
TA450
Secureworks
:
COBALT ULSTER
Iranian MOIS-affiliated cyber-espionage and disruption group.
Targets
25
Sectors
16
Threat types
1
GIRs covered
8/480
Active since
2017
Pin to atlas
Watch
Share
Export
Also tracked as
6 vendor names · 7 other aliases
Open Rosetta Stone
CrowdStrike
HELIX KITTEN
Mandiant
Temp.Zagros
Microsoft
Mango Sandstorm
MITRE
G0069
Proofpoint
TA450
Secureworks
COBALT ULSTER
UNATTRIBUTED ALIASES
STATIC KITTEN
MERCURY
Seedworm
ATK51
Earth Vetala
Boggy Serpens
ITG17
Victimology
Geographic footprint · 25 countries
Region filter
Export
origin · Iran
targeted countries · 25
ASIA ·
17
United Arab Emirates
·
Afghanistan
·
Armenia
·
Azerbaijan
·
Georgia
·
Israel
·
India
·
Iraq
·
Jordan
·
Oman
·
Pakistan
·
Palestine
·
Saudi Arabia
·
Syria
·
Tajikistan
·
Turkmenistan
·
Türkiye
EUROPE ·
5
Albania
·
Germany
·
United Kingdom
·
Malta
·
Netherlands
AFRICA ·
1
Egypt
OCEANIA ·
1
Tokelau
AMERICAS ·
1
United States
REGIONS
Middle East & North Africa
Sectors targeted
16 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Aviation
22 actors
Financial Services
74 actors
Healthcare
47 actors
Pharmaceutical
27 actors
Technology
60 actors
Telecom
72 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Oil and Gas
21 actors
Education & Research
62 actors
Real Estate
10 actors
Hospitality
33 actors
Agriculture & Food
18 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 58 techniques
Resource Development
· 1
T1583.006
Web Services
Initial Access
· 4
T1190
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
Execution
· 11
T1047
Windows Management Instrumentation
Persistence
· 3
T1137.001
Office Template Macros
Credential Access
· 7
T1003
OS Credential Dumping
Discovery
· 6
T1016
System Network Configuration Discovery
Lateral Movement
· 2
T1210
Exploitation of Remote Services
Collection
· 3
T1113
Screen Capture
T1560
Archive Collected Data
T1560.001
Archive via Utility
Exfiltration
· 2
T1041
Exfiltration Over C2 Channel
T1567.002
Exfiltration to Cloud Storage
Command And Control
· 7
T1071.001
Web Protocols
T1090
Proxy
Defense Impairment
· 1
T1685
Disable or Modify Tools
Stealth
· 11
T1027
Obfuscated Files or Information
GIR coverage
8 / 480 requirements satisfied
Open matrix
4 · 4 - Fraud, Identity Theft and Unauthorized Access
4.4.2
5 · 5 - Adversary Tactics and Activities
5.2.1
5.2.5
5.2.6
5.2.10
5.5.1
6 · 6 - Threats Impacting Industry or Region
6.1.6
6.2.5
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
58 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.005
Visual Basic
T1059.006
Python
T1059.007
JavaScript
T1203
Exploitation for Client Execution
T1204.001
Malicious Link
T1204.004
Malicious Copy and Paste
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
T1003.001
LSASS Memory
T1003.004
LSA Secrets
T1003.005
Cached Domain Credentials
T1552.001
Credentials In Files
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
T1033
System Owner/User Discovery
T1049
System Network Connections Discovery
T1057
Process Discovery
T1083
File and Directory Discovery
T1518
Software Discovery
T1534
Internal Spearphishing
T1102.002
Bidirectional Communication
T1104
Multi-Stage Channels
T1105
Ingress Tool Transfer
T1219.002
Remote Desktop Software
T1571
Non-Standard Port
T1027.003
Steganography
T1027.004
Compile After Delivery
T1027.010
Command Obfuscation
T1036.005
Match Legitimate Resource Name or Location
T1140
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution
T1218.003
CMSTP
T1218.005
Mshta
T1218.011
Rundll32
T1684.001
Impersonation