ATT&CKReferencesFalconFeeds_MuddyWaterPSRust_Mar2026

FalconFeeds_MuddyWaterPSRust_Mar2026

FalconFeeds.io. (2026, March 6). MuddyWater in the Iran–Israel Cyber War: From PowerShell Scripts to Rust Implants. Retrieved March 12, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1219.002
Remote Desktop Software
GroupMuddyWater

MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration.

T1571
Non-Standard Port
GroupMuddyWater

MuddyWater has used ports 8043 and 8848 for botnet C2 communication.

T1590.004
Network Topology
GroupMuddyWater

MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.