logo

Iranian APT MuddyWater Uses Dindoor Malware to Target U.S. Networks

ID: 6108043a-80ad-5588-9c9e-22caa3cd3dbd

STIX ID: report--6108043a-80ad-5588-9c9e-22caa3cd3dbd

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-03-09

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**MuddyWater Dindoor campaign (2026):** A state-linked Iranian APT (MuddyWater/Seedworm) conducted a cyber espionage campaign beginning in early 2026 against multiple organizations — including a U.S. airport, a U.S. bank, a Canadian non-profit, and a defense/aerospace-related software supplier — deploying a previously undocumented Deno-based backdoor dubbed Dindoor and a Python backdoor (Fakeset), abusing legitimate tools like Rclone for suspected data exfiltration; researchers published IoCs (several domains) and recommended monitoring for Deno processes, Rclone activity, and persistence/backdoor behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.