Iran-linked APT targets US critical sectors with new backdoors
ID: 1b7a7bd1-e0fc-51bf-9e5d-d2554205baf2
STIX ID: report--1b7a7bd1-e0fc-51bf-9e5d-d2554205baf2
Feed Name: Help Net Security
Symantec and Carbon Black attribute ongoing intrusions since February 2026 to the Iran-linked APT Seedworm (MuddyWater), which has been observed inside US and Israeli-linked networks (including a US bank, an airport, non-profits and a defense supplier) using new backdoors—Dindoor (Deno-based) and Fakeset (Python)—and signed binaries, performing reconnaissance and data exfiltration to Wasabi via rclone; an exposed VPS harvested by researchers revealed extensive C2 tooling, exploitation of multiple CVEs, password-spraying, and broad targeting across regional governments and organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
