Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software Company

Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and (TL-2026-0757), also tracked as Dindoor Campaign, is a critical-severity advanced persistent threat campaign, first published 2026-06-10. It is attributed to MuddyWater (Iran) with high confidence, affects Deno Land Deno JavaScript/TypeScript runtime, references 2 CVEs (CVE-2023-6895, CVE-2017-7921), maps to 22 MITRE ATT&CK techniques (T1016, T1021, T1027), and is covered by 9 detection rules and 40 indicators of compromise.

Key facts for TL-2026-0757

Threat ID
TL-2026-0757
Also known as
Dindoor Campaign, Iran Cyber Threat Activity Against U.S. Organizations (Feb-Mar 2026)
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-06-10
Last reviewed
2026-06-10
Attribution
MuddyWater
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
financial, transportation, aviation, defense, aerospace, software, non-profit, government
Target regions
North America, Middle East
Detection rules
9
Indicators of compromise
40

Malware and tooling in Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

Malware and tooling: AnyDesk, HTTPSnoop, PDQ, Rclone - S1040, ScreenConnect, reGeorg

Seedworm (MuddyWater), a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), compromised the networks of a U.S. bank, a U.S. airport, a U.S. defense/aerospace software supplier, and U.S./Canadian non-profits beginning early February 2026, amid escalation following U.S./Israeli military strikes on Iran. The campaign introduced two previously unknown backdoors — the Deno-runtime JavaScript implant Dindoor and the Python implant Fakeset — both signed with code-signing certificates ('Amy Cherne' and 'Donald Gay') reused from prior Seedworm Stagecomp/Darkcomp operations, with malware staged on Backblaze B2 and data exfiltrated via Rclone to Wasabi cloud storage.

How Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and works

In a report published March 5, 2026, Symantec's Threat Hunter Team (Security.com) documented an active in-the-wild intrusion campaign by the Iranian state-sponsored APT group Seedworm — widely tracked as MuddyWater, Temp Zagros, and Static Kitten — against multiple U.S. critical-sector organizations. Activity began in early February 2026 and continued through publication, coinciding with a sharp escalation in U.S.-Israel-Iran tensions including a February 28, 2026 U.S./Israeli military operation against Iran and the March 1, 2026 reported killing of Iran's Supreme Leader. Confirmed victims include a U.S. bank, a U.S. airport, a U.S. software company that supplies the defense and aerospace industries (with Israeli operations that appear to be the primary target), and non-governmental organizations in both the U.S. and Canada.

The campaign introduced two previously undocumented backdoors. Dindoor is a JavaScript backdoor executed via the Deno runtime — an unconventional execution environment that lets the actor run command-and-control logic outside traditional shell tooling — and was deployed on the software supplier's Israeli branch, the U.S. bank, and the Canadian NGO. Fakeset is a Python backdoor found on the U.S. airport and a non-profit, distributed from Backblaze cloud-storage servers. Both implants were signed with code-signing certificates issued to 'Amy Cherne'; Fakeset additionally used a certificate issued to 'Donald Gay' that Seedworm had previously used to sign its Stagecomp loader and Darkcomp payload, providing high-confidence attribution to the same actor. Microsoft detects Fakeset as Trojan:Python/MuddyWater.DB!MTB and Kaspersky as Backdoor.Python.MuddyWater.a.

The operators relied on legitimate cloud infrastructure for both staging and exfiltration: malware and second-stage payloads were hosted in Backblaze B2 buckets (gitempire and elvenforest), C2 used HTTPS application-layer protocols blended with legitimate cloud traffic, and the actors attempted to exfiltrate data from the software company using the Rclone utility to an attacker-controlled Wasabi cloud-storage bucket. Tradecraft consistent with Seedworm and the broader Iranian-aligned ecosystem in this reporting included spear-phishing and 'honeytrap' social-engineering for initial access and credential theft, remote-access tooling (AnyDesk, ScreenConnect, PDQ), ReGeorg web shells, the HTTPSnoop traffic tool, and a custom browser credential stealer. Symantec situates this campaign within a wider surge of Iranian APT and hacktivist activity against U.S., Canadian, and Israeli targets by groups including Marshtreader (Agrius/Agonizing Serpens), Druidfly (Homeland Justice), Damselfly (Charming Kitten), Mantis (Arid Viper), Handala, and DieNet — some of which exploited internet-exposed cameras via CVE-2023-6895 and CVE-2017-7921. Defenders should hunt for anomalous Deno runtime installations and execution, suspicious Python/JavaScript implant behavior, Rclone activity to Wasabi/Backblaze, and the documented file-hash, domain, and certificate indicators.

MITRE ATT&CK techniques used in TL-2026-0757

Discovery

T1016 System Network Configuration Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1505 Server Software Component; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Collection

T1074 Data Staged

Credential Access

T1110 Brute Force; T1555 Credentials from Password Stores

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

defense-impairment

T1553 Subvert Trust Controls

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

  • Deno Land — Deno JavaScript/TypeScript runtime
    Vulnerable versions: abused as malware execution host (not a Deno vulnerability)
  • Hikvision — IP Cameras
    Vulnerable versions: firmware affected by CVE-2017-7921
    Fixed in: vendor-patched firmware
  • Multiple IoT camera vendors — Internet-exposed IP cameras
    Vulnerable versions: affected by CVE-2023-6895
    Fixed in: vendor-patched firmware

Remediation for Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

Patches

  • Patch internet-exposed IP cameras and IoT against CVE-2023-6895 and CVE-2017-7921 to remove a known Iranian-aligned access vector

Immediate actions

  • Block the documented Backblaze B2 staging domains (gitempire and elvenforest backblazeb2.com buckets) and C2 domains (uppdatefile.com, serialmenot.com, moonzonet.com) at the perimeter and DNS layer
  • Hunt for and block the documented Dindoor, Fakeset, Stagecomp, and Darkcomp SHA256 file hashes across endpoints
  • Revoke trust / alert on binaries signed with the 'Amy Cherne' and 'Donald Gay' code-signing certificates
  • Hunt for anomalous Deno runtime installation and execution, and unexpected Python interpreter activity launching network connections

Workarounds

  • Application-allowlist scripting runtimes so Deno/Python cannot execute from user-writable paths
  • Disable or tightly scope remote-access tools (AnyDesk/ScreenConnect/PDQ) not required for business operations

Longer-term hardening

  • Deploy EDR with behavioral detection for living-off-the-land scripting runtimes (Deno, Node, Python) used as implant hosts
  • Implement phishing-resistant MFA to blunt spear-phishing and honeytrap credential theft
  • Monitor and restrict use of Rclone, AnyDesk, ScreenConnect, and PDQ; alert on Rclone connections to Wasabi/Backblaze endpoints
  • Egress-filter and inspect outbound HTTPS to consumer cloud-storage providers from server and OT-adjacent segments

CVEs associated with Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

CVE-2023-6895, CVE-2017-7921

Weaknesses (CWE) in Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

CWE-798, CWE-287, CWE-1188

Timeline of Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

  • Seedworm (MuddyWater) first observed; later attributed as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS).
  • Iranian-aligned activity including Marshtreader internet-exposed camera scanning and municipal-government password spraying observed.
  • Phoenix backdoor spear-phishing campaign attributed to the Iranian-aligned ecosystem.
  • Academics and Middle East experts targeted in spear-phishing operations.
  • Seedworm begins intrusion activity on U.S. bank, U.S. airport, U.S. defense/aerospace software supplier, and U.S./Canadian non-profits.
  • Dindoor (Deno-runtime JavaScript backdoor) and Fakeset (Python backdoor) deployed; payloads staged on Backblaze B2 buckets.
  • U.S./Israeli military operation against Iran; cyber activity intensifies in parallel.
  • Iran's Supreme Leader reported killed in an airstrike; Iranian-aligned cyber retaliation broadens against U.S., Canadian, and Israeli targets.
  • Attempted data exfiltration from the software company via Rclone to an attacker-controlled Wasabi cloud-storage bucket.
  • Symantec/Security.com publishes report attributing the campaign to Seedworm and documenting Dindoor and Fakeset backdoors plus IOCs.
  • The Hacker News, SecurityWeek, The Register, Help Net Security, and others corroborate the campaign and certificate-reuse attribution.

Sources cited for Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

Threats related to Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and

Detection coverage for TL-2026-0757

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0757 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-0757

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats