logo

Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations

ID: b737e9ca-cc12-573e-92e0-3f042283574a

STIX ID: report--b737e9ca-cc12-573e-92e0-3f042283574a

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Broadcom Symantec reports that Iran-linked APT MuddyWater (Seedworm) has been conducting an active campaign since February 2026 against multiple U.S. organizations across sectors (banks, airports, nonprofits, and a software supplier), deploying a new Dindoor backdoor (Deno runtime, signed with a certificate issued to “Amy Cherne”) and a Python backdoor called Fakeset, using cloud services (Backblaze, Wasabi) and Rclone for exfiltration attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.