Iran intelligence backdoored US bank, airport, software outfit networks
ID: 272aa8cf-9c5a-5b5f-b446-373583dcdc7c
STIX ID: report--272aa8cf-9c5a-5b5f-b446-373583dcdc7c
Feed Name: The Register (Security)
**Summary:** Security researchers attribute a cross-border intrusion campaign to the Iranian-affiliated MuddyWater (Seedworm) group, finding persistent access in multiple US, Canadian, and Israeli organizations. Analysts uncovered two backdoors (Dindoor — a Deno-based backdoor — and a Python backdoor called Fakeset), observed attempted data exfiltration using Rclone to Wasabi, and tied activity to MuddyWater via reused code-signing certificates; the presence predating recent hostilities raises concern about potential pivot to disruptive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
