logo

MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

ID: a5da403a-0d3e-57a3-864d-dce17078c741

STIX ID: report--a5da403a-0d3e-57a3-864d-dce17078c741

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

In early 2026 the Iranian APT MuddyWater conducted cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S. software company, deploying a new backdoor called Dindoor and exfiltrating data using Rclone to Wasabi; the group is reported to be actively exploiting CVE-2024-30088 (listed on CISA's KEV) and leveraging legitimate tools to blend with normal enterprise activity, posing increased risk to critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.