logo

Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threats

ID: e61c70d1-4984-508a-a53c-64d1693bd897

STIX ID: report--e61c70d1-4984-508a-a53c-64d1693bd897

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Iran-linked APT Seedworm (aka MuddyWater/Temp Zagros/Static Kitten) has been observed compromising U.S. and Israeli environments since early February 2026, deploying novel backdoors (Dindoor using the Deno runtime, Python Fakeset) and reusing code-signing certificates tied to previous Seedworm tooling; investigators also observed attempted data exfiltration to cloud storage via Rclone and evidence of wiper activity. The report highlights abuse of legitimate cloud platforms for staging/C2, certificate-based attribution links to historic Seedworm operations, and recommends heightened monitoring for anomalous cloud transfers, use of Deno runtimes, and code-signed binaries as well as standard mitigations (MFA, backups, hardened identity systems).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.