Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threat Activity
ID: fbf8c295-88b9-5617-bd2b-b3b30a692617
STIX ID: report--fbf8c295-88b9-5617-bd2b-b3b30a692617
Feed Name: cybersecurityNews.com
Seedworm, an Iranian state-aligned APT, has been observed operating inside multiple U.S. and allied networks since early February 2026, deploying new backdoors (Dindoor and Fakeset), reusing previously seen signing certificates, attempting data exfiltration via Rclone to cloud storage, and leveraging lateral access through multinational infrastructure; this activity is occurring alongside Iran-aligned hacktivist DDoS campaigns and warrants strengthened MFA, outbound transfer monitoring, cloud access restrictions, web application firewalling, and immutable backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
