A new INCD report reveals how the Iranian cyber group has intensified its attacks on Israel following the Swords of Iron War.
The group has adopted advanced tactics, developed custom tools, and expanded its targeting of key sectors, posing a growing strategic threat.
Iranian cyberattack group MuddyWater has undergone significant evolution since its inception. A new report by the Israel National Cyber Directorate (INCD) provides an in-depth analysis of the group’s activities within the Israeli cyber domain in 2024, focusing on their tactics, techniques, and procedures (TTPs), tools, and primary attack targets. T
Discovered in 2017, MuddyWater, which operates under the Iranian Ministry of Intelligence and Security (MOIS), primarily focuses on countries in the Middle East, but has also operated in the US and in Africa. Following the outbreak of the Swords of Iron War, a marked increase in cyber activity attributed to the MuddyWater group was observed within Israel.
The INCD report notes that this resurgence follows a period of relative inactivity, which may have been influenced by the public exposure of the group's members at the CyberTech Tel Aviv conference in 2023. The exposure, which was incorporated into a speech delivered by the Head of the Israel National Cyber Directorate (INCD), Gabi Portnoy, heightened awareness of the group’s operations and their potential implications.