logo

Already Inside: How Iran's MuddyWater APT Quietly Embedded Itself in U.S. Critical Infrastructure

ID: e98ab013-218a-5a25-a319-a8624e7b54bf

STIX ID: report--e98ab013-218a-5a25-a319-a8624e7b54bf

Feed Name: NoHackie

Threat Score
90/100

Date Published: 2026-03-09

Date Updated: 2026-04-19

...
...

This report summarizes March 2026 disclosures that MuddyWater (an Iranian state-linked APT) had long-standing access to multiple high-value targets — including a U.S. bank, a U.S. airport, an Israeli-linked defense software firm, and a Canadian nonprofit — using novel and living-off-the-land tooling (Dindoor, Fakeset, Deno/Python runtimes), signed binaries, cloud-based exfiltration to Wasabi/Backblaze, and diverse C2 mechanisms (Telegram, Ethereum smart contracts), highlighting broad operational scale, supply-chain risk, exposed infrastructure, and potential for cyber access to enable kinetic effects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.