Iran's MuddyWater Hackers Hit US Firms with New 'Dindoor' Backdoor
ID: 2e987a72-5ec1-513c-852c-9c3a35dd7fcf
STIX ID: report--2e987a72-5ec1-513c-852c-9c3a35dd7fcf
Feed Name: Infosecurity Magazine (News)
Symantec/Carbon Black Threat Hunters uncovered an active campaign since early February attributed to Iran-linked MuddyWater targeting multiple US and Canadian organizations (a bank, an airport, NGOs and a defense-sector software subsidiary). The attackers deployed a Deno-based backdoor named “Dindoor” and a Python backdoor “Fakeset,” attempted cloud exfiltration using Rclone to a Wasabi bucket, and reused code-signing certificates previously linked to MuddyWater, providing forensic ties to the group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
