Iranian APT MuddyWater Uses Dindoor Malware to Target U.S. Networks
ID: 6108043a-80ad-5588-9c9e-22caa3cd3dbd
STIX ID: report--6108043a-80ad-5588-9c9e-22caa3cd3dbd
Feed Name: SOCRadar Blog
**MuddyWater Dindoor campaign (2026):** A state-linked Iranian APT (MuddyWater/Seedworm) conducted a cyber espionage campaign beginning in early 2026 against multiple organizations — including a U.S. airport, a U.S. bank, a Canadian non-profit, and a defense/aerospace-related software supplier — deploying a previously undocumented Deno-based backdoor dubbed Dindoor and a Python backdoor (Fakeset), abusing legitimate tools like Rclone for suspected data exfiltration; researchers published IoCs (several domains) and recommended monitoring for Deno processes, Rclone activity, and persistence/backdoor behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
