logo

Iran-linked APT targets US critical sectors with new backdoors

ID: 1b7a7bd1-e0fc-51bf-9e5d-d2554205baf2

STIX ID: report--1b7a7bd1-e0fc-51bf-9e5d-d2554205baf2

Feed Name: Help Net Security

Threat Score
88/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Symantec and Carbon Black attribute ongoing intrusions since February 2026 to the Iran-linked APT Seedworm (MuddyWater), which has been observed inside US and Israeli-linked networks (including a US bank, an airport, non-profits and a defense supplier) using new backdoors—Dindoor (Deno-based) and Fakeset (Python)—and signed binaries, performing reconnaissance and data exfiltration to Wasabi via rclone; an exposed VPS harvested by researchers revealed extensive C2 tooling, exploitation of multiple CVEs, password-spraying, and broad targeting across regional governments and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.