Iran’s MuddyWater Hackers Target US Firms with New Dindoor Backdoor
ID: 7387607f-1560-5a02-8bf8-43c4a5e4f297
STIX ID: report--7387607f-1560-5a02-8bf8-43c4a5e4f297
Feed Name: HackRead
Researchers attribute an ongoing espionage campaign beginning in early February 2026 to the Iran-aligned APT MuddyWater, which has compromised multiple U.S. organizations across sectors including banking and aviation. Attackers rely on spear-phishing and social engineering to gain access, move laterally using stolen credentials and legitimate Windows/admin tools, and deploy a custom backdoor called Dindoor to blend with legitimate traffic and maintain long-term persistence for intelligence collection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
