Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign) — Threadlinqs Intelligence
As of 2026-06-10, Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign) is a high-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0748 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
A sustained, measurable elevation in global cyber risk driven by Iranian state-aligned operations amid the 2026 Iran conflict. The MOIS-linked MuddyWater (Seedworm) APT expanded Western targeting in
Avertium's Cyber Threat Assessment, corroborated by Microsoft, Google Threat Intelligence Group (GTIG), Palo Alto Unit 42, SentinelOne, Recorded Future Insikt Group, Check Point, Broadcom/Symantec, and CISA, reports a coordinated, multi-track Iranian state-aligned cyber campaign running in parallel with the kinetic escalation of the Iran conflict that intensified in late February 2026. The campaign is characterized by faster operational tempo, blended tradecraft (espionage + disruption + criminal proxies), and an increased willingness to accept operational risk, with expanded direct and indirect targeting of the U.S. and allied entities.
The central observed operator is MuddyWater (a.k.a. Seedworm, Mango Sandstorm, Static Kitten, TEMP.Zagros, Earth Vetala, TA450, MERCURY; MITRE G0069), assessed as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017. In February 2026, Symantec's Threat Hunter Team observed MuddyWater compromising a U.S. bank, a U.S. airport, a Canadian non-profit, a U.S. non-profit, and the Israeli operations of a U.S. software company that supplies the defense and aerospace sectors. The intrusions deployed two new implants: Dindoor, a previously undocumented backdoor that abuses the Deno secure JavaScript/TypeScript runtime for execution and was signed with a code-signing certificate issued to 'Amy Cherne'; and Fakeset, a Python backdoor staged from Backblaze B2 cloud storage buckets and signed with certificates issued to 'Amy Cherne' and 'Donald Gay'. The 'Donald Gay' certificate had previously signed the Stagecomp and Darkcomp malware families attributed to Seedworm, providing the attribution linkage. Rclone was used to copy collected/backup data to Wasabi cloud storage for exfiltration.
The group's tradecraft remains heavily PowerShell- and LOLBin-centric (mshta.exe, regsvr32.exe, rundll32.exe, certutil.exe), pairing macro-enabled spear-phishing documents and exposed/unpatched edge-device exploitation for initial access with registry Run-key persistence, credential and browser-data theft, software/security-tool discovery, lateral movement, and encrypted HTTP/S C2 over standard and non-standard ports. Across 2025-2026 MuddyWater progressively shed commodity RMM reliance in favor of purpose-built malware (BugSleep, StealthCache, Phoenix, the Fooder loader, MuddyViper) and advanced to Rust-based payloads (RustyWater, CHAR) that use asynchronous JSON/base64/XOR-encrypted C2, process injection, layered encryption, randomized sleep/jitter, and 20+ security-product checks. Reporting also notes commercial satellite internet (Starlink) and legitimate cloud/CDN/messaging infrastructure abuse for low-signal C2. GTIG separately documents Iranian APT use of generative AI for reconnaissance, phishing-lure creation, and malware development, raising scale and quality of operations.
The assessment warns of elevated probability of destructive wiper activity and critical-infrastructure attacks if tensions escalate further, and recommends defenders treat this as a sustained threat period rather than a one-off alert, prioritizing behavioral detection over signature reliance.
Target sectors: financial, aviation, transportation, energy, utilities, telecom, healthcare, technology, cloud, msp, government, defense
Target regions: North America, Middle East, Europe, Israel, Canada
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, T1590, T1583, T1583, T1588, T1588, T1190, T1566, T1566, T1059, T1059