logo

Iran’s MuddyWater Hackers Target US Firms with New Dindoor Backdoor

ID: 7387607f-1560-5a02-8bf8-43c4a5e4f297

STIX ID: report--7387607f-1560-5a02-8bf8-43c4a5e4f297

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Waqas

...
...

Researchers attribute an ongoing espionage campaign beginning in early February 2026 to the Iran-aligned APT MuddyWater, which has compromised multiple U.S. organizations across sectors including banking and aviation. Attackers rely on spear-phishing and social engineering to gain access, move laterally using stolen credentials and legitimate Windows/admin tools, and deploy a custom backdoor called Dindoor to blend with legitimate traffic and maintain long-term persistence for intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.