Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset Backdoors
Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting (TL-2026-0176), also tracked as Operation Seedworm 2026, is a critical-severity advanced persistent threat campaign, first published 2026-03-06. It is attributed to MuddyWater (Iran) with high confidence, affects Multiple U.S. Banking Institution, maps to 33 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 47 indicators of compromise.
Key facts for TL-2026-0176
- Threat ID
- TL-2026-0176
- Also known as
- Operation Seedworm 2026, MuddyWater February 2026 Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-06
- Last reviewed
- 2026-03-06
- Attribution
- MuddyWater
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- banking, aviation, defense, aerospace, software, nonprofit, healthcare, energy, government
- Target regions
- North America, Middle East, Israel, Canada
- Detection rules
- 9
- Indicators of compromise
- 47
Malware and tooling in Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting
Malware and tooling: RIP (Phoenix) Ransomware, Trojan.Darkcomp, Trojan.Dindoor, Trojan.Fakeset, Trojan.Stagecomp, AnyDesk, Dindoor, Fakeset, PDQ, Rclone - S1040, ScreenConnect, reGeorg
Iranian MOIS-affiliated threat group Seedworm (MuddyWater) has been conducting an active cyber espionage campaign against U.S. critical infrastructure since early February 2026, deploying custom backdoors Dindoor (Deno-based) and Fakeset (Python-based) against a U.S. bank, airport, defense/aerospace software supplier with Israeli operations, and multiple nonprofits. The campaign leverages legitimate tools for lateral movement and cloud storage services for data exfiltration.
How Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting works
Seedworm, also tracked as MuddyWater, Mango Sandstorm, TEMP.Zagros, and Static Kitten (MITRE G0069), is a subordinate element within Iran's Ministry of Intelligence and Security (MOIS) that has been conducting cyber espionage operations since at least 2017. In early February 2026, Symantec/Broadcom researchers identified active Seedworm intrusions on the networks of multiple U.S. organizations, including a banking institution, an airport, a defense/aerospace software company with Israeli operations, and nonprofit organizations in both the U.S. and Canada.
The campaign employs two previously undocumented backdoors. Dindoor (Trojan.Dindoor) is a novel backdoor that leverages the Deno JavaScript/TypeScript runtime for execution, representing an evolution in the group's tooling toward modern cross-platform runtimes. It was found on the Israeli outpost of a software company, a U.S. bank, and a Canadian nonprofit. Fakeset (Trojan.Fakeset) is a Python-based backdoor discovered on the airport and a U.S. nonprofit's networks. Both malware families were signed with certificates issued to 'Amy Cherne', while Fakeset additionally used a certificate issued to 'Donald Gay' — a signing identity previously linked to Seedworm's Stagecomp downloader and Darkcomp backdoor.
The attack chain begins with spear-phishing emails containing malicious attachments or links, leveraging researched organizational intelligence for social engineering. Upon gaining initial access, the operators deploy Dindoor or Fakeset for persistent remote access. Lateral movement is achieved through RDP, SSH, VNC, and web shells (ReGeorg). The group also deploys legitimate remote access tools including AnyDesk, ScreenConnect, and PDQ to blend with normal administrative traffic.
For data exfiltration, Seedworm uses Rclone to transfer stolen data to Wasabi cloud storage, and downloads additional payloads from Backblaze S3 buckets (gitempire and elvenforest). Stagecomp serves as a downloader for the Darkcomp backdoor, providing an additional persistence and access layer.
The campaign's timing — coinciding with escalating U.S.-Iran geopolitical tensions following coordinated U.S./Israeli military strikes on February 28, 2026 — suggests both intelligence collection and pre-positioning for potential destructive operations. Seedworm has historically conducted wiper attacks (BibiWiper) and has destructive capabilities through Stagecomp and related tooling. The FBI, CISA, and UK NCSC have formally attributed MuddyWater to MOIS operations since 2018.
Defenders should prioritize monitoring for Deno runtime execution in unexpected contexts, Python-based backdoor activity, certificate-signed binaries from unknown issuers (Amy Cherne, Donald Gay), Rclone exfiltration to cloud storage, and connections to the identified C2 domains and Backblaze infrastructure.
---
**Revalidated on 2026-03-12**
Substantial new intelligence has emerged in the week since this threat was published, significantly expanding the understanding of Seedworm/MuddyWater's operational scope and confirming this campaign as part of a strategic Iranian cyber posture preceding and following Operation Epic Fury.
### Ctrl-Alt-Intel VPS Forensics (March 2026) Forensic analysis of a compromised MuddyWater VPS hosted in the Netherlands revealed three previously undocumented custom C2 frameworks: KeyC2 (Python/UDP on port 1269 with SQLite backend), PersianC2 (HTTP polling with JSON API and AES staging), and ArenaC2 (FastAPI/uvicorn with AES-256-CBC encryption presenting decoy news websites in English, French, and German). The VPS also contained Tsundere botnet infrastructure that leverages Ethereum smart contracts (address 0x2B77671cfEE4907776a95abbb9681eee598c102E) for dynamic C2 resolution via WebSocket connections, demonstrating novel blockchain-based command-and-control. Additional C2 IPs identified include 162.0.230[.]185, 194.11.246[.]101, 185.236.25[.]119, and 193.17.183[.]126. The server contained modified FortiOS exploits (CVE-2024-55591 PoC altered to create persistent 'FortiSetup' admin accounts), evidence of active exploitation of CVE-2026-1731 (BeyondTrust RCE), CVE-2026-1281 (Ivanti EPMM), CVE-2025-68613 (n8n RCE), and reconnaissance tools (Subfinder, Nuclei, Shodan CLI). Targeting extended beyond U.S. infrastructure to Israeli healthcare/immigration organizations, EgyptAir, Jordanian government webmail, UAE energy firms, Portuguese government Exchange servers (compromised with Neo-reGeorg webshells), and U.S. company Clearview AI. Exfiltrated data included Egyptian passport/visa information, King Khalid Airport receipts, WhatsApp data, and biometric access control configurations.
### Check Point Research: MOIS-Cybercrime Nexus (March 10, 2026) Check Point Research identified Dindoor as a variant of the 'Tsundere' botnet family, establishing a direct technical lineage. More significantly, the report documented MOIS actors' strategic pivot to leveraging commercial cybercriminal infrastructure for plausible deniability: shared code-signing certificates ('Amy Cherne'/'Donald Gay') link MuddyWater's custom tooling to CastleLoader malware-as-a-service operations; the October 2025 Shamir Medical Center attack was attributed to Iranian operators using Qilin ransomware-as-a-service; and Handala persona deployed Rhadamanthys commercial infostealer alongside custom wipers against Israeli targets.
### Operation Olalampo: Concurrent MENA Campaign (January 26, 2026) Group-IB documented a concurrent MuddyWater campaign (Operation Olalampo) targeting MENA organizations via phishing with malicious Office macros, deploying multiple novel payloads: CHAR (a Rust backdoor using Telegram bot 'stager_51_bot' for C2, with evidence of AI-assisted development via emoji debug strings), GhostFetch and HTTP_VIP (downloaders), and GhostBackDoor (advanced implant). This campaign ran in parallel with the U.S. infrastructure intrusions, demonstrating MuddyWater's capacity for simultaneous multi-theater operations.
### Broader MOIS Ecosystem Escalation The Handala/Void Manticore wiper attack on Stryker Corporation (March 11, 2026) claiming 200,000 systems destroyed via Microsoft Intune remote wipe, combined with IP camera exploitation surges across Israel and Gulf states (CVE-2017-7921, CVE-2021-33044, CVE-2021-36260), demonstrates that MuddyWater's espionage operations are one component of a coordinated multi-actor MOIS cyber offensive. CISA, FBI, DC3, and NSA issued a joint statement warning of potential targeted Iranian cyber activity against U.S. critical infrastructure, urging heightened vigilance for defense industrial base organizations with Israeli ties.
### New CVEs Under Active Exploitation CVE-2026-1731 (BeyondTrust RCE), CVE-2026-1281 (Ivanti EPMM code injection), CVE-2025-68613 (n8n RCE), CVE-2025-52691 (SmarterMail file upload), CVE-2025-9316 (N-Central improper access control), CVE-2024-55591 (FortiOS authentication bypass), CVE-2024-23113 (FortiOS format string), CVE-2022-42475 (FortiOS heap overflow).
MITRE ATT&CK techniques used in TL-2026-0176
credential-access
T1003 OS Credential Dumping; T1110 Brute Force; T1187 Forced Authentication; T1555 Credentials from Password Stores
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1087 Account Discovery
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
collection
T1074 Data Staged; T1560 Archive Collected Data
initial-access
T1190 Exploit Public-Facing Application; T1566 Phishing
impact
T1486 Data Encrypted for Impact; T1561 Disk Wipe
persistence
T1547 Boot or Logon Autostart Execution
stealth
resource-development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
reconnaissance
T1598 Phishing for Information
defense-impairment
Affected products and versions in Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting
- Multiple — U.S. Banking Institution
Vulnerable versions: Network infrastructure - Multiple — U.S. Airport Infrastructure
Vulnerable versions: Network infrastructure - Multiple — U.S. Defense/Aerospace Software Supplier (Israeli Operations)
Vulnerable versions: Network infrastructure - Multiple — U.S. and Canadian Nonprofit Organizations
Vulnerable versions: Network infrastructure
Remediation for Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting
Immediate actions
- Block C2 domains uppdatefile.com, serialmenot.com, moonzonet.com at DNS and perimeter
- Block Backblaze S3 endpoints gitempire.s3.us-east-005.backblazeb2.com and elvenforest.s3.us-east-005.backblazeb2.com
- Hunt for Dindoor and Fakeset file hashes across all endpoints
- Audit for unauthorized Deno runtime installations and Python-based backdoors
- Revoke and rotate credentials for any compromised accounts
- Scan for certificates signed by Amy Cherne or Donald Gay
Workarounds
- Block Rclone execution via application whitelisting policies
- Disable legacy authentication protocols
- Restrict outbound connections to cloud storage platforms from production networks
- Implement conditional access policies based on location and device risk
Longer-term hardening
- Deploy EDR with behavioral detection for Deno-based and Python-based backdoor execution
- Implement network segmentation for critical infrastructure systems
- Enable multi-factor authentication on all remote access services
- Restrict and monitor legitimate remote access tools (AnyDesk, ScreenConnect, PDQ)
- Implement DLP policies to detect Rclone and cloud storage exfiltration
- Deploy web application firewalls with updated rulesets for web shell detection
Timeline of Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting
Showing the 20 most recent tracked events.
- Seedworm/MuddyWater first observed conducting cyber espionage operations, attributed to Iranian MOIS
- FBI, CISA, and UK NCSC publish joint advisory AA22-055A formally attributing MuddyWater to Iranian MOIS
- Seedworm conducts academic targeting campaign (June-August 2025) for credential harvesting and intelligence collection
- Phoenix backdoor spear-phishing campaign launched targeting 100+ MENA government entities with PDQ remote access tool
- Seedworm targets foreign policy experts for intelligence collection using social engineering
- MuddyWater initiates Operation Olalampo, deploying AI-assisted Rust backdoor CHAR via Telegram bot C2 (stager_51_bot), GhostFetch, GhostBackDoor, and HTTP_VIP loaders against MENA government and private sector targets [Source: https://www.group-ib.com/blog/muddywater-operation-olalampo/]
- Seedworm begins active intrusions on U.S. critical infrastructure networks including bank, airport, and defense software supplier
- Dindoor (Deno-based) and Fakeset (Python-based) backdoors deployed across victim networks with Amy Cherne and Donald Gay certificates
- Group-IB publishes detailed analysis of Operation Olalampo, attributing the MENA campaign to MuddyWater with high confidence based on C2 infrastructure overlap and malicious macro consistency [Source: https://www.group-ib.com/blog/muddywater-operation-olalampo/]
- U.S. and Israel launch Operation Epic Fury / Roaring Lion, striking 1,250 Iranian military targets; Iran''s internet connectivity drops to 1-4%; MuddyWater''s pre-positioned U.S. infrastructure access becomes strategically significant [Source: https://www.attackiq.com/2026/03/05/operation-epic-fury/]
- U.S./Israel coordinated military strikes on Iran; Seedworm activity intensifies on compromised networks
- Post-strike activity surge observed with increased lateral movement and data exfiltration attempts via Rclone to Wasabi cloud storage
- Israeli strike hits alleged IRGC cyber headquarters in Tehran, directly targeting Iranian offensive cyber capabilities [Source: https://fieldeffect.com/blog/seedworm-iran-cyber-activity]
- Symantec/Broadcom publishes detailed threat intelligence report exposing Seedworm campaign with full IOCs and malware analysis
- Multiple security outlets (Help Net Security, Infosecurity Magazine, SecurityAffairs) publish analyses of Symantec''s Dindoor/Fakeset findings, expanding public awareness of MuddyWater''s U.S. infrastructure intrusions [Source: https://www.helpnetsecurity.com/2026/03/06/seedworm-muddywater-backdoors-victims/]
- Cybersecurity Dive reports state-linked actors had pre-positioned inside U.S. networks before Operation Epic Fury, confirming Seedworm''s intrusions were strategic preparation rather than opportunistic [Source: https://www.cybersecuritydive.com/news/state-linked-actors-targeted-us-networks-in-lead-up-to-iran-war/814190/]
- Check Point Research publishes ''Iranian MOIS Actors & the Cyber Crime Connection'' linking MuddyWater''s Dindoor to the Tsundere botnet family and documenting MOIS use of cybercriminal infrastructure (Qilin RaaS, Rhadamanthys, CastleLoader) for plausible deniability [Source: https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/]
- Handala/Void Manticore (MOIS-affiliated) claims wiper attack on Stryker Corporation via Microsoft Intune remote wipe, alleging 200,000 systems destroyed and 50TB stolen, demonstrating broader MOIS ecosystem escalation alongside MuddyWater espionage [Source: https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/]
- Ctrl-Alt-Intel publishes forensic analysis of compromised MuddyWater VPS in Netherlands revealing three custom C2 frameworks (KeyC2, PersianC2, ArenaC2), Tsundere botnet with Ethereum smart contract C2 resolution, exploitation of CVE-2026-1731/CVE-2026-1281/CVE-2025-68613, and broader targeting of Israeli, Jordanian, Egyptian, UAE, and Portuguese entities [Source: https://ctrlaltintel.com/threat%20research/MuddyWater/]
- As of 2026-05-29, this Seedworm/MuddyWater (MOIS, MITRE G0069) Dindoor/Fakeset espionage campaign against U.S. critical infrastructure remains active; vendor reporting (Symantec, Help Net, Hacker News, The Register) traced it to Feb 2026 and described intrusions "continuing in recent days." The actor is undisrupted and running parallel ops (RustyWater, false-flag Chaos ransomware); no CVE/patch applies.
Sources cited for Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting
- Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company
- Iran intelligence backdoored US bank, airport networks
- MuddyWater Targets Orgs With Fresh Malware Amid Rising Tensions
- MITRE ATT&CK - MuddyWater (G0069)
- CISA Advisory AA22-055A: Iranian Government-Sponsored Actors Conduct Cyber Operations
- RustyWater: MuddyWater APT Targets Israeli Infrastructure
- MuddyWater APT Profile: Tactics, Malware, And MITRE ATT&CK
- MuddyWater: Operation Olalampo
- Unmasking MuddyWater New Malware Toolkit
- MuddyWater Threat Actor Profile - Malpedia
Threats related to Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting
- Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software Company
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
- Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure
- Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign)
- Iran Conflict Cyber Operations: MuddyWater (Seedworm) Deploys New Dindoor and Fakeset Backdoors Against US Banks, Airports, Non-Profits, and Defense/Aerospace Software Providers (Feb-Mar 2026)
- MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering, DWAgent Persistence, Game.exe RAT Trojanizing Microsoft WebView2APISample (Operation Olalampo Link)
Detection coverage for TL-2026-0176
As of 2026-03-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0176 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.