logo

Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor

ID: 4a80dff7-ad92-5bad-ae12-8735b25c60bc

STIX ID: report--4a80dff7-ad92-5bad-ae12-8735b25c60bc

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report details suspected Iranian state-sponsored activity by MuddyWater (Seedworm) embedding in U.S. and Israeli-linked networks, including deployment of a novel Deno-based backdoor called “Dindoor” and a Python backdoor “Fakeset” (signed with certificates linked to other MuddyWater malware), an attempted Rclone-based data exfiltration, and broad exploitation/scanning of IP cameras using multiple CVEs; it contextualizes this activity amid escalating regional conflict and provides mitigation advice for organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.