Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software Company
Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and (TL-2026-0757), also tracked as Dindoor Campaign, is a critical-severity advanced persistent threat campaign, first published 2026-06-10. It is attributed to MuddyWater (Iran) with high confidence, affects Deno Land Deno JavaScript/TypeScript runtime, references 2 CVEs (CVE-2023-6895, CVE-2017-7921), maps to 22 MITRE ATT&CK techniques (T1016, T1021, T1027), and is covered by 9 detection rules and 40 indicators of compromise.
Key facts for TL-2026-0757
- Threat ID
- TL-2026-0757
- Also known as
- Dindoor Campaign, Iran Cyber Threat Activity Against U.S. Organizations (Feb-Mar 2026)
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-06-10
- Last reviewed
- 2026-06-10
- Attribution
- MuddyWater
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- financial, transportation, aviation, defense, aerospace, software, non-profit, government
- Target regions
- North America, Middle East
- Detection rules
- 9
- Indicators of compromise
- 40
Malware and tooling in Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
Malware and tooling: AnyDesk, HTTPSnoop, PDQ, Rclone - S1040, ScreenConnect, reGeorg
Seedworm (MuddyWater), a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), compromised the networks of a U.S. bank, a U.S. airport, a U.S. defense/aerospace software supplier, and U.S./Canadian non-profits beginning early February 2026, amid escalation following U.S./Israeli military strikes on Iran. The campaign introduced two previously unknown backdoors — the Deno-runtime JavaScript implant Dindoor and the Python implant Fakeset — both signed with code-signing certificates ('Amy Cherne' and 'Donald Gay') reused from prior Seedworm Stagecomp/Darkcomp operations, with malware staged on Backblaze B2 and data exfiltrated via Rclone to Wasabi cloud storage.
How Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and works
In a report published March 5, 2026, Symantec's Threat Hunter Team (Security.com) documented an active in-the-wild intrusion campaign by the Iranian state-sponsored APT group Seedworm — widely tracked as MuddyWater, Temp Zagros, and Static Kitten — against multiple U.S. critical-sector organizations. Activity began in early February 2026 and continued through publication, coinciding with a sharp escalation in U.S.-Israel-Iran tensions including a February 28, 2026 U.S./Israeli military operation against Iran and the March 1, 2026 reported killing of Iran's Supreme Leader. Confirmed victims include a U.S. bank, a U.S. airport, a U.S. software company that supplies the defense and aerospace industries (with Israeli operations that appear to be the primary target), and non-governmental organizations in both the U.S. and Canada.
The campaign introduced two previously undocumented backdoors. Dindoor is a JavaScript backdoor executed via the Deno runtime — an unconventional execution environment that lets the actor run command-and-control logic outside traditional shell tooling — and was deployed on the software supplier's Israeli branch, the U.S. bank, and the Canadian NGO. Fakeset is a Python backdoor found on the U.S. airport and a non-profit, distributed from Backblaze cloud-storage servers. Both implants were signed with code-signing certificates issued to 'Amy Cherne'; Fakeset additionally used a certificate issued to 'Donald Gay' that Seedworm had previously used to sign its Stagecomp loader and Darkcomp payload, providing high-confidence attribution to the same actor. Microsoft detects Fakeset as Trojan:Python/MuddyWater.DB!MTB and Kaspersky as Backdoor.Python.MuddyWater.a.
The operators relied on legitimate cloud infrastructure for both staging and exfiltration: malware and second-stage payloads were hosted in Backblaze B2 buckets (gitempire and elvenforest), C2 used HTTPS application-layer protocols blended with legitimate cloud traffic, and the actors attempted to exfiltrate data from the software company using the Rclone utility to an attacker-controlled Wasabi cloud-storage bucket. Tradecraft consistent with Seedworm and the broader Iranian-aligned ecosystem in this reporting included spear-phishing and 'honeytrap' social-engineering for initial access and credential theft, remote-access tooling (AnyDesk, ScreenConnect, PDQ), ReGeorg web shells, the HTTPSnoop traffic tool, and a custom browser credential stealer. Symantec situates this campaign within a wider surge of Iranian APT and hacktivist activity against U.S., Canadian, and Israeli targets by groups including Marshtreader (Agrius/Agonizing Serpens), Druidfly (Homeland Justice), Damselfly (Charming Kitten), Mantis (Arid Viper), Handala, and DieNet — some of which exploited internet-exposed cameras via CVE-2023-6895 and CVE-2017-7921. Defenders should hunt for anomalous Deno runtime installations and execution, suspicious Python/JavaScript implant behavior, Rclone activity to Wasabi/Backblaze, and the documented file-hash, domain, and certificate indicators.
MITRE ATT&CK techniques used in TL-2026-0757
Discovery
T1016 System Network Configuration Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1505 Server Software Component; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Collection
Credential Access
T1110 Brute Force; T1555 Credentials from Password Stores
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
defense-impairment
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
- Deno Land — Deno JavaScript/TypeScript runtime
Vulnerable versions: abused as malware execution host (not a Deno vulnerability) - Hikvision — IP Cameras
Vulnerable versions: firmware affected by CVE-2017-7921
Fixed in: vendor-patched firmware - Multiple IoT camera vendors — Internet-exposed IP cameras
Vulnerable versions: affected by CVE-2023-6895
Fixed in: vendor-patched firmware
Remediation for Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
Patches
- Patch internet-exposed IP cameras and IoT against CVE-2023-6895 and CVE-2017-7921 to remove a known Iranian-aligned access vector
Immediate actions
- Block the documented Backblaze B2 staging domains (gitempire and elvenforest backblazeb2.com buckets) and C2 domains (uppdatefile.com, serialmenot.com, moonzonet.com) at the perimeter and DNS layer
- Hunt for and block the documented Dindoor, Fakeset, Stagecomp, and Darkcomp SHA256 file hashes across endpoints
- Revoke trust / alert on binaries signed with the 'Amy Cherne' and 'Donald Gay' code-signing certificates
- Hunt for anomalous Deno runtime installation and execution, and unexpected Python interpreter activity launching network connections
Workarounds
- Application-allowlist scripting runtimes so Deno/Python cannot execute from user-writable paths
- Disable or tightly scope remote-access tools (AnyDesk/ScreenConnect/PDQ) not required for business operations
Longer-term hardening
- Deploy EDR with behavioral detection for living-off-the-land scripting runtimes (Deno, Node, Python) used as implant hosts
- Implement phishing-resistant MFA to blunt spear-phishing and honeytrap credential theft
- Monitor and restrict use of Rclone, AnyDesk, ScreenConnect, and PDQ; alert on Rclone connections to Wasabi/Backblaze endpoints
- Egress-filter and inspect outbound HTTPS to consumer cloud-storage providers from server and OT-adjacent segments
CVEs associated with Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
Weaknesses (CWE) in Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
CWE-798, CWE-287, CWE-1188
Timeline of Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
- Seedworm (MuddyWater) first observed; later attributed as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS).
- Iranian-aligned activity including Marshtreader internet-exposed camera scanning and municipal-government password spraying observed.
- Phoenix backdoor spear-phishing campaign attributed to the Iranian-aligned ecosystem.
- Academics and Middle East experts targeted in spear-phishing operations.
- Seedworm begins intrusion activity on U.S. bank, U.S. airport, U.S. defense/aerospace software supplier, and U.S./Canadian non-profits.
- Dindoor (Deno-runtime JavaScript backdoor) and Fakeset (Python backdoor) deployed; payloads staged on Backblaze B2 buckets.
- U.S./Israeli military operation against Iran; cyber activity intensifies in parallel.
- Iran's Supreme Leader reported killed in an airstrike; Iranian-aligned cyber retaliation broadens against U.S., Canadian, and Israeli targets.
- Attempted data exfiltration from the software company via Rclone to an attacker-controlled Wasabi cloud-storage bucket.
- Symantec/Security.com publishes report attributing the campaign to Seedworm and documenting Dindoor and Fakeset backdoors plus IOCs.
- The Hacker News, SecurityWeek, The Register, Help Net Security, and others corroborate the campaign and certificate-reuse attribution.
Sources cited for Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
- Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company
- Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
- Iranian APT Hacked US Airport, Bank, Software Company
- Iran intelligence backdoored US bank, airport networks
- Iran-linked APT targets US critical sectors with new backdoors
- MuddyWater's Dindoor Backdoor: Iranian APT Targets U.S. Organizations via Deno Runtime and Cloud Storage
- Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
- Iranian APT group MuddyWater targets multiple US companies
- CISA Advisory AA22-055A: Iranian Government-Sponsored MuddyWater APT
Threats related to Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and
- Iranian APT MuddyWater (Seedworm) Deploys Novel Dindoor & Fakeset Backdoors Against U.S. Critical Infrastructure
- Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and Fakeset Backdoors
- Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign)
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
- Iran Conflict Cyber Operations: MuddyWater (Seedworm) Deploys New Dindoor and Fakeset Backdoors Against US Banks, Airports, Non-Profits, and Defense/Aerospace Software Providers (Feb-Mar 2026)
- MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering, DWAgent Persistence, Game.exe RAT Trojanizing Microsoft WebView2APISample (Operation Olalampo Link)
Detection coverage for TL-2026-0757
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0757 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0757
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.