Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software Company — Threadlinqs Intelligence
As of 2026-06-10, Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software Company is a critical-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0757 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Seedworm (MuddyWater), a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), compromised the networks of a U.S. bank, a U.S. airport, a U.S. defense/aerospace software
In a report published March 5, 2026, Symantec's Threat Hunter Team (Security.com) documented an active in-the-wild intrusion campaign by the Iranian state-sponsored APT group Seedworm — widely tracked as MuddyWater, Temp Zagros, and Static Kitten — against multiple U.S. critical-sector organizations. Activity began in early February 2026 and continued through publication, coinciding with a sharp escalation in U.S.-Israel-Iran tensions including a February 28, 2026 U.S./Israeli military operation against Iran and the March 1, 2026 reported killing of Iran's Supreme Leader. Confirmed victims include a U.S. bank, a U.S. airport, a U.S. software company that supplies the defense and aerospace industries (with Israeli operations that appear to be the primary target), and non-governmental organizations in both the U.S. and Canada.
The campaign introduced two previously undocumented backdoors. Dindoor is a JavaScript backdoor executed via the Deno runtime — an unconventional execution environment that lets the actor run command-and-control logic outside traditional shell tooling — and was deployed on the software supplier's Israeli branch, the U.S. bank, and the Canadian NGO. Fakeset is a Python backdoor found on the U.S. airport and a non-profit, distributed from Backblaze cloud-storage servers. Both implants were signed with code-signing certificates issued to 'Amy Cherne'; Fakeset additionally used a certificate issued to 'Donald Gay' that Seedworm had previously used to sign its Stagecomp loader and Darkcomp payload, providing high-confidence attribution to the same actor. Microsoft detects Fakeset as Trojan:Python/MuddyWater.DB!MTB and Kaspersky as Backdoor.Python.MuddyWater.a.
The operators relied on legitimate cloud infrastructure for both staging and exfiltration: malware and second-stage payloads were hosted in Backblaze B2 buckets (gitempire and elvenforest), C2 used HTTPS application-layer protocols blended with legitimate cloud traffic, and the actors attempted to exfiltrate data from the software company using the Rclone utility to an attacker-controlled Wasabi cloud-storage bucket. Tradecraft consistent with Seedworm and the broader Iranian-aligned ecosystem in this reporting included spear-phishing and 'honeytrap' social-engineering for initial access and credential theft, remote-access tooling (AnyDesk, ScreenConnect, PDQ), ReGeorg web shells, the HTTPSnoop traffic tool, and a custom browser credential stealer. Symantec situates this campaign within a wider surge of Iranian APT and hacktivist activity against U.S., Canadian, and Israeli targets by groups including Marshtreader (Agrius/Agonizing Serpens), Druidfly (Homeland Justice), Damselfly (Charming Kitten), Mantis (Arid Viper), Handala, and DieNet — some of which exploited internet-exposed cameras via CVE-2023-6895 and CVE-2017-7921. Defenders should hunt for anomalous Deno runtime installations and execution, suspicious Python/JavaScript implant behavior, Rclone activity to Wasabi/Backblaze, and the documented file-hash, domain, and certificate indicators.
Weaknesses (CWE)
CWE-798, CWE-287, CWE-1188
Target sectors: financial, transportation, aviation, defense, aerospace, software, non-profit, government
Target regions: North America, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2023-6895, CVE-2017-7921, T1595, T1588, T1583, T1566, T1566, T1190, T1059, T1059, T1204, T1547