Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset Backdoors — Threadlinqs Intelligence
As of 2026-05-30, Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset Backdoors is a critical-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 47 indicators of compromise.
Threat ID: TL-2026-0176 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Iranian MOIS-affiliated threat group Seedworm (MuddyWater) has been conducting an active cyber espionage campaign against U.S. critical infrastructure since early February 2026, deploying custom
Seedworm, also tracked as MuddyWater, Mango Sandstorm, TEMP.Zagros, and Static Kitten (MITRE G0069), is a subordinate element within Iran's Ministry of Intelligence and Security (MOIS) that has been conducting cyber espionage operations since at least 2017. In early February 2026, Symantec/Broadcom researchers identified active Seedworm intrusions on the networks of multiple U.S. organizations, including a banking institution, an airport, a defense/aerospace software company with Israeli operations, and nonprofit organizations in both the U.S. and Canada.
The campaign employs two previously undocumented backdoors. Dindoor (Trojan.Dindoor) is a novel backdoor that leverages the Deno JavaScript/TypeScript runtime for execution, representing an evolution in the group's tooling toward modern cross-platform runtimes. It was found on the Israeli outpost of a software company, a U.S. bank, and a Canadian nonprofit. Fakeset (Trojan.Fakeset) is a Python-based backdoor discovered on the airport and a U.S. nonprofit's networks. Both malware families were signed with certificates issued to 'Amy Cherne', while Fakeset additionally used a certificate issued to 'Donald Gay' — a signing identity previously linked to Seedworm's Stagecomp downloader and Darkcomp backdoor.
The attack chain begins with spear-phishing emails containing malicious attachments or links, leveraging researched organizational intelligence for social engineering. Upon gaining initial access, the operators deploy Dindoor or Fakeset for persistent remote access. Lateral movement is achieved through RDP, SSH, VNC, and web shells (ReGeorg). The group also deploys legitimate remote access tools including AnyDesk, ScreenConnect, and PDQ to blend with normal administrative traffic.
For data exfiltration, Seedworm uses Rclone to transfer stolen data to Wasabi cloud storage, and downloads additional payloads from Backblaze S3 buckets (gitempire and elvenforest). Stagecomp serves as a downloader for the Darkcomp backdoor, providing an additional persistence and access layer.
The campaign's timing — coinciding with escalating U.S.-Iran geopolitical tensions following coordinated U.S./Israeli military strikes on February 28, 2026 — suggests both intelligence collection and pre-positioning for potential destructive operations. Seedworm has historically conducted wiper attacks (BibiWiper) and has destructive capabilities through Stagecomp and related tooling. The FBI, CISA, and UK NCSC have formally attributed MuddyWater to MOIS operations since 2018.
Defenders should prioritize monitoring for Deno runtime execution in unexpected contexts, Python-based backdoor activity, certificate-signed binaries from unknown issuers (Amy Cherne, Donald Gay), Rclone exfiltration to cloud storage, and connections to the identified C2 domains and Backblaze infrastructure.
---
**Revalidated on 2026-03-12**
Substantial new intelligence has emerged in the week since this threat was published, significantly expanding the understanding of Seedworm/MuddyWater's operational scope and confirming this campaign as part of a strategic Iranian cyber posture preceding and following Operation Epic Fury.
### Ctrl-Alt-Intel VPS Forensics (March 2026)
Forensic analysis of a compromised MuddyWater VPS hosted in the Netherlands revealed three previously undocumented custom C2 frameworks: KeyC2 (Python/UDP on port 1269 with SQLite backend), PersianC2 (HTTP polling with JSON API and AES staging), and ArenaC2 (FastAPI/uvicorn with AES-256-CBC encryption presenting decoy news websites in English, French, and German). The VPS also contained Tsundere botnet infrastructure that leverages Ethereum smart contracts (address 0x2B77671cfEE4907776a95abbb9681eee598c102E) for dynamic C2 resolution via WebSocket connections, demonstrating novel blockchain-based command-and-control. Additional C2 IPs identified include 162.0.230[.]185, 194.11.246[.]101, 185.236.25[.]119, and 193.17.183[.]126. The server contained modified Forti
Target sectors: banking, aviation, defense, aerospace, software, nonprofit, healthcare, energy, government
Target regions: North America, Middle East, Israel, Canada
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 47 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1566, T1566, T1190, T1059, T1059, T1059, T1053, T1204, T1547, T1574