Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
ID: b737e9ca-cc12-573e-92e0-3f042283574a
STIX ID: report--b737e9ca-cc12-573e-92e0-3f042283574a
Feed Name: Security Affairs
Threat Score
Broadcom Symantec reports that Iran-linked APT MuddyWater (Seedworm) has been conducting an active campaign since February 2026 against multiple U.S. organizations across sectors (banks, airports, nonprofits, and a software supplier), deploying a new Dindoor backdoor (Deno runtime, signed with a certificate issued to “Amy Cherne”) and a Python backdoor called Fakeset, using cloud services (Backblaze, Wasabi) and Rclone for exfiltration attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
