ATT&CKReferencesFalconFeeds_Iran_Mar2026

FalconFeeds_Iran_Mar2026

FalconFeeds.io. (2026, March 5). The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict. Retrieved March 9, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1090
Proxy
GroupMuddyWater

MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France.

T1219.002
Remote Desktop Software
GroupMuddyWater

MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration.

T1534
Internal Spearphishing
GroupMuddyWater

MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.