logo

Iran's MuddyWater Hackers Hit US Firms with New 'Dindoor' Backdoor

ID: 2e987a72-5ec1-513c-852c-9c3a35dd7fcf

STIX ID: report--2e987a72-5ec1-513c-852c-9c3a35dd7fcf

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

...
...

Symantec/Carbon Black Threat Hunters uncovered an active campaign since early February attributed to Iran-linked MuddyWater targeting multiple US and Canadian organizations (a bank, an airport, NGOs and a defense-sector software subsidiary). The attackers deployed a Deno-based backdoor named “Dindoor” and a Python backdoor “Fakeset,” attempted cloud exfiltration using Rclone to a Wasabi bucket, and reused code-signing certificates previously linked to MuddyWater, providing forensic ties to the group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.