logo

Iran intelligence backdoored US bank, airport, software outfit networks

ID: 272aa8cf-9c5a-5b5f-b446-373583dcdc7c

STIX ID: report--272aa8cf-9c5a-5b5f-b446-373583dcdc7c

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2026-03-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Summary:** Security researchers attribute a cross-border intrusion campaign to the Iranian-affiliated MuddyWater (Seedworm) group, finding persistent access in multiple US, Canadian, and Israeli organizations. Analysts uncovered two backdoors (Dindoor — a Deno-based backdoor — and a Python backdoor called Fakeset), observed attempted data exfiltration using Rclone to Wasabi, and tied activity to MuddyWater via reused code-signing certificates; the presence predating recent hostilities raises concern about potential pivot to disruptive operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.