Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
ID: 4a80dff7-ad92-5bad-ae12-8735b25c60bc
STIX ID: report--4a80dff7-ad92-5bad-ae12-8735b25c60bc
Feed Name: The Hacker News
The report details suspected Iranian state-sponsored activity by MuddyWater (Seedworm) embedding in U.S. and Israeli-linked networks, including deployment of a novel Deno-based backdoor called “Dindoor” and a Python backdoor “Fakeset” (signed with certificates linked to other MuddyWater malware), an attempted Rclone-based data exfiltration, and broad exploitation/scanning of IP cameras using multiple CVEs; it contextualizes this activity amid escalating regional conflict and provides mitigation advice for organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
