Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure

Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & (TL-2026-0198), also tracked as Operation Seedworm 2026, is a critical-severity advanced persistent threat campaign, first published 2026-03-09. It is attributed to MuddyWater (Iran) with high confidence, affects Multiple U.S. Banking Institution, maps to 25 MITRE ATT&CK techniques (T1018, T1021, T1027), and is covered by 9 detection rules and 45 indicators of compromise.

Key facts for TL-2026-0198

Threat ID
TL-2026-0198
Also known as
Operation Seedworm 2026, Dindoor Campaign
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-03-09
Last reviewed
2026-03-09
Attribution
MuddyWater
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
banking, aviation, defense, aerospace, nonprofit, software, government, healthcare
Target regions
United States, Canada, Israel, Jordan, United Arab Emirates, Egypt
Detection rules
9
Indicators of compromise
45

Malware and tooling in Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor &

Malware and tooling: Darkcomp, Fakeset, Stagecomp, Tsundere Botnet - S9034, AnyDesk, Ethereum-based C2 resolution, PDQ, Rclone - S1040, ScreenConnect, reGeorg

Iran's MuddyWater (Seedworm/MOIS) APT group has compromised networks of a U.S. bank, airport, defense software supplier, and NGOs using two previously unknown backdoors: Dindoor (Deno-based BYOR) and Fakeset (Python-based). The campaign, active since early February 2026, escalated following U.S.-Israeli military operations against Iran.

How Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & works

Symantec's Threat Hunter Team uncovered a campaign by Seedworm (also tracked as MuddyWater, Temp.Zagros, Static Kitten), an Iranian APT linked to Iran's Ministry of Intelligence and Security (MOIS), targeting U.S. critical infrastructure and allied organizations.

The campaign deploys two previously unknown backdoors:

**Dindoor** is a novel backdoor that leverages the Deno JavaScript/TypeScript runtime as a 'Bring Your Own Runtime' (BYOR) evasion strategy. By bundling a legitimate runtime, the malware executes commands through a trusted process, bypassing application whitelisting and behavioral detections that target standard scripting engines like PowerShell or cmd.exe. Dindoor samples are digitally signed with a certificate issued to 'Amy Cherne', a previously unknown identity in public threat intelligence. Dindoor was deployed against the Israeli branch of a U.S. defense/aerospace software supplier, a U.S. bank, and a Canadian non-profit organization.

**Fakeset** is a Python-based backdoor downloaded from Backblaze cloud storage servers (gitempire.s3.us-east-005.backblazeb2.com and elvenforest.s3.us-east-005.backblazeb2.com). Fakeset samples are signed with certificates attributed to both 'Amy Cherne' and 'Donald Gay'. The 'Donald Gay' certificate has been previously associated with Stagecomp and Darkcomp malware used by Seedworm, as confirmed by Google, Microsoft, and Kaspersky. Fakeset was deployed against a U.S. airport and a U.S. non-profit organization.

The **Stagecomp/Darkcomp** loader chain is also present in this campaign. Stagecomp is a loader that downloads and executes the Darkcomp backdoor. Both are signed with the 'Donald Gay' certificate, establishing a clear link to Seedworm operations.

Data exfiltration was attempted using Rclone, an open-source command-line tool, copying data to Wasabi cloud storage buckets. The exfiltration command pattern observed was: 'rclone copy CSIDL_DRIVE_FIXED\backups wasabi:[bucket]:/192.168.0.x'.

Investigation of exposed infrastructure revealed a VPS hosted in the Netherlands containing evidence of broader targeting including Israeli healthcare organizations, EgyptAir, Jordanian government entities, UAE companies, and Jewish/Israeli NGOs. The exposed VPS also showed Ethereum-based C2 resolution mechanisms.

The campaign began in early February 2026 and activity continued through the date of public disclosure on March 5, 2026. The timing is significant: U.S. and Israeli coordinated military operations against Iran began on February 28, 2026, and Iran's Supreme Leader was killed in an airstrike on March 1, 2026. Seedworm's pre-existing presence on U.S. and Israeli networks prior to hostilities places the group in a position to launch destructive operations.

Additional tools observed include remote access tools (AnyDesk, ScreenConnect, PDQ), the ReGeorg web shell, and credential-stealing utilities targeting browser credentials and mailbox access. Password spraying campaigns were also documented.

---

**Revalidated on 2026-03-12**

Since initial publication on March 5, 2026, revalidation on March 12 confirms the Dindoor/Fakeset campaign remains ACTIVE with no evidence of infrastructure takedown or certificate revocation. Critically, MuddyWater is now confirmed to be running at least four concurrent campaigns in early 2026: (1) the Dindoor/Fakeset campaign against U.S. critical infrastructure documented here, (2) Operation Olalampo (Group-IB, Jan 26 2026) targeting MENA with CHAR (Rust, AI-assisted), GhostFetch, HTTP_VIP, and GhostBackDoor — some using Telegram bot C2, (3) the RustyWater campaign (CloudSEK, Jan 2026) deploying a Rust-based RAT against Israeli government/military/financial/telecom via Hebrew-language spear-phishing, and (4) the UDPGangster campaign (FortiGuard, Dec 2025) using UDP-based C2 against Turkey/Israel/Azerbaijan. This operational tempo — four distinct campaigns, six+ novel malware families, four programming languages (JavaScript/Deno, Python, Rust, C++), multiple C2 protocols (HTTPS, UDP, Telegram, Ethereum) — is unprecedented for MuddyWater and suggests a significant expansion in resources and tasking, likely driven by the Iran-U.S./Israel military escalation. Amazon threat intelligence has correlated MuddyWater cyber operations directly with kinetic missile strikes, confirming the cyber-kinetic nexus assessment in the original report. The Amy Cherne and Donald Gay code signing certificates remain unrevoked as of March 12, 2026, representing a persistent threat vector.

MITRE ATT&CK techniques used in TL-2026-0198

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

lateral-movement

T1021 Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1078 Valid Accounts

exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

execution

T1059 Command and Scripting Interpreter

command-and-control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

collection

T1074 Data Staged; T1114 Email Collection

credential-access

T1110 Brute Force; T1555 Credentials from Password Stores

persistence

T1133 External Remote Services; T1505 Server Software Component

impact

T1485 Data Destruction

defense-impairment

T1553 Subvert Trust Controls

initial-access

T1566 Phishing

resource-development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor &

  • Multiple — U.S. Banking Institution
    Vulnerable versions: Network infrastructure
  • Multiple — U.S. Airport
    Vulnerable versions: Network infrastructure
  • Multiple — U.S. Defense/Aerospace Software Supplier (Israeli operations)
    Vulnerable versions: Network infrastructure
  • Multiple — U.S. Non-Profit Organization
    Vulnerable versions: Network infrastructure
  • Multiple — Canadian Non-Profit Organization
    Vulnerable versions: Network infrastructure

Remediation for Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor &

Immediate actions

  • Block Backblaze staging domains gitempire.s3.us-east-005.backblazeb2.com and elvenforest.s3.us-east-005.backblazeb2.com at proxy/firewall
  • Block C2 domains uppdatefile.com, serialmenot.com, and moonzonet.com at DNS and proxy
  • Hunt for Deno runtime processes (deno.exe) executing from non-standard paths
  • Search for digitally signed binaries with certificates issued to Amy Cherne or Donald Gay
  • Monitor for Rclone exfiltration to Wasabi cloud storage
  • Revoke and block AnyDesk, ScreenConnect, and PDQ if not authorized

Workarounds

  • Block execution of Deno runtime from user-writable directories
  • Restrict Rclone and similar sync tools via application control policies
  • Enforce MFA on all externally-facing services and VPN endpoints

Longer-term hardening

  • Deploy EDR with behavioral detection for BYOR (Bring Your Own Runtime) techniques
  • Implement application whitelisting that detects bundled runtime abuse
  • Enable enhanced logging for PowerShell, JavaScript, and Python execution
  • Implement network segmentation for critical infrastructure systems
  • Deploy cloud access security broker (CASB) to detect unauthorized cloud storage exfiltration
  • Conduct threat hunting for Seedworm TTPs across all endpoint telemetry

Timeline of Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor &

  • MuddyWater deploys UDPGangster backdoor in Turkey-Israel-Azerbaijan campaign, demonstrating UDP-based C2 evasion — a precursor showing accelerating tooling development ahead of Dindoor/Fakeset
  • RustyWater Rust-based RAT deployed against Israeli government, military, financial, telecom, and maritime targets via Hebrew-language spear-phishing, demonstrating MuddyWater''s shift to memory-safe languages
  • Operation Olalampo begins — MuddyWater targets MENA organizations with 4 new malware families (CHAR Rust backdoor, GhostFetch, HTTP_VIP, GhostBackDoor), some using Telegram bot C2 and AI-assisted code development
  • Seedworm (MuddyWater) initiates intrusion activity against U.S. critical infrastructure networks including a bank, airport, defense software supplier, and NGOs
  • Dindoor backdoor deployed against Israeli branch of U.S. defense/aerospace software supplier, signed with Amy Cherne certificate
  • Fakeset Python backdoor deployed against U.S. airport and non-profit via Backblaze cloud storage staging (gitempire and elvenforest buckets)
  • Data exfiltration attempted using Rclone to Wasabi cloud storage buckets from compromised networks
  • U.S. and Israeli coordinated military operations against Iran begin, raising stakes of Seedworm pre-positioned access on critical infrastructure
  • Iran Supreme Leader killed in airstrike, significantly escalating geopolitical tensions and potential for destructive cyber operations
  • Handala Hack Team (Iranian-aligned) claims breach of Sharjah National Oil Corporation (UAE) and Israel Opportunity Energy, exfiltrating 1.3TB — part of broader Iranian cyber escalation post-military strikes
  • Multiple security vendors (SecurityWeek, The Hacker News, The Register, Infosecurity Magazine) confirm and amplify Symantec findings
  • Symantec Threat Hunter Team publishes detailed report on Seedworm campaign with IOCs and technical analysis of Dindoor and Fakeset backdoors
  • Cybersecurity Dive reports that Amazon threat intelligence correlates MuddyWater cyber activity with physical missile strikes, establishing a direct cyber-kinetic operational link
  • Help Net Security reports additional targets identified via exposed VPS: Israeli healthcare, EgyptAir, Jordanian government, UAE companies
  • Campaign remains active with continued intrusion activity against U.S. and allied networks
  • Revalidation confirms campaign remains ACTIVE with no evidence of certificate revocation or infrastructure takedown. MuddyWater operating at least 4 concurrent campaigns (Dindoor/Fakeset, RustyWater, Olalampo, UDPGangster follow-on)
  • As of 2026-05-29, this MuddyWater/Seedworm threat remains ACTIVE: Rapid7 (May 6) confirmed the actor running Chaos ransomware false-flag ops reusing the same Donald Gay cert, and CISA AA26-097A (Apr 7) confirmed escalating Iranian attacks on US critical infrastructure. No certificate revocation, takedown, or campaign conclusion has been reported.

Sources cited for Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor &

Threats related to Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor &

Detection coverage for TL-2026-0198

As of 2026-03-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0198 across Splunk SPL, Microsoft KQL and Sigma, covering 45 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats