Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign)

Iranian State-Aligned Global Cyber Operations Surge Amid (TL-2026-0748), also tracked as Dindoor Campaign, is a high-severity advanced persistent threat campaign, first published 2026-03-17. It is attributed to MuddyWater (Iran) with high confidence, affects Multiple U.S. and allied critical infrastructure and enterprise, maps to 29 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-0748

Threat ID
TL-2026-0748
Also known as
Dindoor Campaign, Fakeset Campaign, Iran Conflict Global Cyber Operations Risk
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-03-17
Last reviewed
2026-03-17
Attribution
MuddyWater
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
financial, aviation, transportation, energy, utilities, telecom, healthcare, technology, cloud, msp, government, defense
Target regions
North America, Middle East, Europe, Israel, Canada
Detection rules
9
Indicators of compromise
31

Malware and tooling in Iranian State-Aligned Global Cyber Operations Surge Amid

Malware and tooling: Archer RAT, Fakeset, Tsundere Botnet - S9034, Rclone - S1040

A sustained, measurable elevation in global cyber risk driven by Iranian state-aligned operations amid the 2026 Iran conflict. The MOIS-linked MuddyWater (Seedworm) APT expanded Western targeting in Feb-Mar 2026, backdooring a U.S. bank, a U.S. airport, and a U.S. defense/aerospace software supplier with the new Deno-based Dindoor backdoor and the Python-based Fakeset implant, blending espionage, disruption, and criminal tradecraft.

How Iranian State-Aligned Global Cyber Operations Surge Amid works

Avertium's Cyber Threat Assessment, corroborated by Microsoft, Google Threat Intelligence Group (GTIG), Palo Alto Unit 42, SentinelOne, Recorded Future Insikt Group, Check Point, Broadcom/Symantec, and CISA, reports a coordinated, multi-track Iranian state-aligned cyber campaign running in parallel with the kinetic escalation of the Iran conflict that intensified in late February 2026. The campaign is characterized by faster operational tempo, blended tradecraft (espionage + disruption + criminal proxies), and an increased willingness to accept operational risk, with expanded direct and indirect targeting of the U.S. and allied entities.

The central observed operator is MuddyWater (a.k.a. Seedworm, Mango Sandstorm, Static Kitten, TEMP.Zagros, Earth Vetala, TA450, MERCURY; MITRE G0069), assessed as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017. In February 2026, Symantec's Threat Hunter Team observed MuddyWater compromising a U.S. bank, a U.S. airport, a Canadian non-profit, a U.S. non-profit, and the Israeli operations of a U.S. software company that supplies the defense and aerospace sectors. The intrusions deployed two new implants: Dindoor, a previously undocumented backdoor that abuses the Deno secure JavaScript/TypeScript runtime for execution and was signed with a code-signing certificate issued to 'Amy Cherne'; and Fakeset, a Python backdoor staged from Backblaze B2 cloud storage buckets and signed with certificates issued to 'Amy Cherne' and 'Donald Gay'. The 'Donald Gay' certificate had previously signed the Stagecomp and Darkcomp malware families attributed to Seedworm, providing the attribution linkage. Rclone was used to copy collected/backup data to Wasabi cloud storage for exfiltration.

The group's tradecraft remains heavily PowerShell- and LOLBin-centric (mshta.exe, regsvr32.exe, rundll32.exe, certutil.exe), pairing macro-enabled spear-phishing documents and exposed/unpatched edge-device exploitation for initial access with registry Run-key persistence, credential and browser-data theft, software/security-tool discovery, lateral movement, and encrypted HTTP/S C2 over standard and non-standard ports. Across 2025-2026 MuddyWater progressively shed commodity RMM reliance in favor of purpose-built malware (BugSleep, StealthCache, Phoenix, the Fooder loader, MuddyViper) and advanced to Rust-based payloads (RustyWater, CHAR) that use asynchronous JSON/base64/XOR-encrypted C2, process injection, layered encryption, randomized sleep/jitter, and 20+ security-product checks. Reporting also notes commercial satellite internet (Starlink) and legitimate cloud/CDN/messaging infrastructure abuse for low-signal C2. GTIG separately documents Iranian APT use of generative AI for reconnaissance, phishing-lure creation, and malware development, raising scale and quality of operations.

The assessment warns of elevated probability of destructive wiper activity and critical-infrastructure attacks if tensions escalate further, and recommends defenders treat this as a sustained threat period rather than a one-off alert, prioritizing behavioral detection over signature reliance.

MITRE ATT&CK techniques used in TL-2026-0748

Credential Access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1518 Software Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1219 Remote Access Tools; T1571 Non-Standard Port; T1573 Encrypted Channel

persistence

T1137 Office Application Startup

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Impact

T1485 Data Destruction

Persistence

T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Collection

T1560 Archive Collected Data

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information

Affected products and versions in Iranian State-Aligned Global Cyber Operations Surge Amid

  • Multiple — U.S. and allied critical infrastructure and enterprise
    Vulnerable versions: energy/utilities; telecom; transportation/aviation; healthcare; financial services; technology/cloud/MSP; government; defense/aerospace

Remediation for Iranian State-Aligned Global Cyber Operations Surge Amid

Patches

  • Patch exposed/internet-facing edge services (VPNs, web applications) and validate perimeter hygiene

Immediate actions

  • Increase monitoring for phishing, anomalous identity activity, and unsanctioned remote access
  • Review and restrict macro, script, and email attachment execution policies (block Office macros from the internet)
  • Hunt for the Dindoor/Fakeset SHA256 hashes and the 'Amy Cherne' / 'Donald Gay' code-signing certificates across the estate
  • Block the known C2 domains and IPs at the perimeter and inspect outbound traffic to Backblaze B2 and Wasabi cloud storage
  • Validate endpoint and identity telemetry coverage and confirm incident escalation paths are current

Workarounds

  • Confirm backup integrity and offline/immutable recovery capability against destructive wiper risk
  • Restrict or monitor execution of unsanctioned developer runtimes (Deno, Node, Python) on enterprise endpoints

Longer-term hardening

  • Deploy EDR with behavioral detection prioritized over signature reliance
  • Enforce least-privilege access and administrative controls; audit and restrict RMM/remote-access tool usage (SimpleHelp, ConnectWise, RemoteUtilities)
  • Implement application allowlisting to constrain LOLBin abuse (mshta, regsvr32, rundll32, certutil) and unsanctioned runtimes (Deno, Python)
  • Constrain and log PowerShell (ScriptBlock/Module logging, Constrained Language Mode)

Timeline of Iranian State-Aligned Global Cyber Operations Surge Amid

  • MuddyWater (Seedworm) assessed active since at least 2017 as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS).
  • CISA, FBI, NSA, USCYBERCOM CNMF and the UK NCSC publish joint advisory AA22-055A formally attributing MuddyWater to Iran's Ministry of Intelligence and Security (MOIS) and detailing PowerShell, side-loading, and C2 tradecraft.
  • CISA, FBI, NSA and DC3 issue a joint advisory warning U.S. critical infrastructure to prepare for heightened Iranian state-aligned and hacktivist cyber activity amid the escalating Iran conflict, citing edge-device targeting and credential abuse.
  • Israel National Cyber Directorate warns of MuddyWater phishing campaign targeting organizational email, amid escalating regional tensions.
  • Symantec traces the start of the U.S./Canada intrusion campaign to early February 2026, targeting a U.S. bank, U.S. airport, Canadian and U.S. non-profits, and a U.S. defense/aerospace software supplier's Israeli operations.
  • Rescana reports the Rust-based RustyWater implant and CHAR backdoor used by MuddyWater against Israeli government and infrastructure with JSON/base64/XOR-encrypted HTTP/S C2.
  • Kinetic escalation of the Iran conflict in late February 2026 coincides with acceleration of state-aligned cyber operations and elevated reconnaissance.
  • Symantec Threat Hunter Team and multiple outlets disclose the new Deno-based Dindoor backdoor and Python-based Fakeset implant, attributing them to MuddyWater via reused 'Amy Cherne' and 'Donald Gay' code-signing certificates.
  • Multiple vendors (SentinelOne, Unit 42, Recorded Future) corroborate Symantec's MuddyWater attribution of the Dindoor and Fakeset implants, noting AI-assisted tooling and reuse of the 'Amy Cherne'/'Donald Gay' code-signing certificates.
  • Avertium publishes its CTA Campaign Assessment characterizing a sustained, multi-track Iranian state-aligned cyber operations surge with faster tempo, blended tradecraft, and expanded Western targeting; warns of wiper and critical-infrastructure escalation risk.

Sources cited for Iranian State-Aligned Global Cyber Operations Surge Amid

Threats related to Iranian State-Aligned Global Cyber Operations Surge Amid

Detection coverage for TL-2026-0748

As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0748 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-0748

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats