Iran Conflict Cyber Operations: MuddyWater (Seedworm) Deploys New Dindoor and Fakeset Backdoors Against US Banks, Airports, Non-Profits, and Defense/Aerospace Software Providers (Feb-Mar 2026)

Iran Conflict Cyber Operations (TL-2026-2114), also tracked as Iran Conflict Cyber Operations Campaign, is a high-severity advanced persistent threat campaign, first published 2026-03-17. It is attributed to MuddyWater (Iran) with high confidence, affects N/A U.S./Canadian banking, aviation, non-profit, and defense-aerospace, maps to 13 MITRE ATT&CK techniques (T1005, T1020, T1059), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2114

Threat ID
TL-2026-2114
Also known as
Iran Conflict Cyber Operations Campaign, Dindoor/Fakeset Campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-03-17
Last reviewed
2026-03-17
Attribution
MuddyWater
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
banking-finance, aviation-transportation, defense-aerospace, non-profit-ngo, technology-software
Target regions
united states of america, canada, israel
Detection rules
9
Indicators of compromise
29

Malware and tooling in Iran Conflict Cyber Operations

Malware and tooling: Darkcomp, Fakeset, Stagecomp, Tsundere Botnet - S9034, Rclone - S1040

Iranian state-aligned actor MuddyWater (Seedworm/TEMP.Zagros/Mango Sandstorm), subordinate to Iran's Ministry of Intelligence and Security, has run a sustained intrusion campaign since early February 2026 against a U.S. bank, a U.S. airport, U.S./Canadian non-profits, and the Israeli operations of a U.S. defense/aerospace software supplier, deploying two previously-unseen backdoors (Dindoor, Fakeset) and attempting cloud-based data exfiltration via Rclone. Avertium assesses this activity as part of a broader, sustained elevation in global cyber risk tied to the Iran-Israel-U.S. conflict that began with coordinated strikes on February 28, 2026.

How Iran Conflict Cyber Operations works

Broadcom's Symantec Threat Hunter Team and independent reporting (The Hacker News, SecurityAffairs) document an Iranian state-sponsored intrusion set, attributed to MuddyWater (aka Seedworm, Earth Vetala, MERCURY, Static Kitten, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill), active against multiple U.S. and allied organizations since early February 2026. Victims include a U.S. bank, a U.S. airport, a U.S. non-governmental organization, a Canadian non-profit, and the Israeli operations of a U.S. software company that supplies the defense and aerospace industry. US Cyber Command and CISA (joint advisory AA22-055A) previously and officially attributed MuddyWater to a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017 with a history of targeting telecommunications, government, defense, and energy-sector organizations for espionage.

The February-March 2026 activity introduces two malware families not previously catalogued in MuddyWater's arsenal. Dindoor is a JavaScript-based backdoor that executes via the Deno secure runtime and was found on the Israeli software-company network, the U.S. bank, and the Canadian non-profit; samples were digitally signed with a certificate issued to "Amy Cherne." Fakeset is a Python-based backdoor deployed against the U.S. airport and non-profit networks, distributed from attacker-controlled Backblaze B2 cloud-storage buckets and signed with certificates ("Amy Cherne," "Donald Gay") that were previously used to sign the related Stagecomp downloader and Darkcomp backdoor -- both malware families independently linked to Seedworm by Google, Microsoft, and Kaspersky. Microsoft detects Fakeset as "Trojan:Python/MuddyWater.DB!MTB" and Kaspersky as "Backdoor.Python.MuddyWater.a." Post-compromise, the actor attempted data exfiltration using the Rclone utility to copy files from a compromised host to a Wasabi cloud-storage bucket, though successful exfiltration could not be confirmed.

Avertium's parallel Cyber Threat Analysis (CTA) assessment, synthesizing reporting from Microsoft DTI, Google GTIG, Unit 42, SentinelOne, Recorded Future, Check Point, Broadcom/Symantec, and CISA/FBI/NSA/DC3, characterizes this as one strand of a measurably elevated, sustained Iranian cyber-operations campaign that accelerated after the February 28, 2026 coordinated U.S.-Israeli military strikes on Iran (which killed Iran's Supreme Leader Ali Khamenei along with senior military leadership). Avertium's broader TTP profile for this campaign cycle -- spear phishing with geopolitical lures, trusted-document/macro abuse, exploitation of unpatched edge devices (VPN/web-facing services), PowerShell-based execution, registry and service-based persistence, encrypted HTTP/S C2 over legitimate cloud/CDN infrastructure, credential harvesting/browser data theft, and network discovery/lateral movement staging -- is consistent with, and corroborated by, the concrete Dindoor/Fakeset intrusion set. Avertium's outlook warns of a three-phase escalation culminating in potential destructive operations against critical infrastructure (energy, utilities, telecom, transportation, healthcare) if the conflict continues. No CVEs are cited by either the Avertium assessment or the Dindoor/Fakeset reporting; this is a TTP- and malware-driven intrusion campaign rather than a single-vulnerability exploit chain.

MITRE ATT&CK techniques used in TL-2026-2114

Collection

T1005 Data from Local System

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Discovery

T1087 Account Discovery

command-and-control

T1090 Proxy

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

defense-impairment

T1553 Subvert Trust Controls

Credential Access

T1555 Credentials from Password Stores

Affected products and versions in Iran Conflict Cyber Operations

  • N/A — U.S./Canadian banking, aviation, non-profit, and defense-aerospace software-supply-chain networks (Israeli operations of a U.S. software company)
    Vulnerable versions: N/A -- TTP- and malware-based intrusion campaign, not a specific software version vulnerability

Remediation for Iran Conflict Cyber Operations

Patches

  • No CVE or vendor patch applies -- this is a TTP- and malware-driven intrusion campaign, not a single-vulnerability exploit chain

Immediate actions

  • Block the identified C2 domains (uppdatefile.com, serialmenot.com, moonzonet.com) and the Backblaze B2 malware-distribution subdomains (gitempire.s3.us-east-005.backblazeb2.com, elvenforest.s3.us-east-005.backblazeb2.com) at DNS/web-proxy layer
  • Hunt endpoint and EDR telemetry for Dindoor (Deno-executed JavaScript) and Fakeset (Python) backdoor artifacts and for binaries signed with the 'Amy Cherne' or 'Donald Gay' certificates
  • Audit and alert on outbound Rclone execution and any transfers to Wasabi or other unauthorized cloud-storage destinations, particularly from banking, aviation, and defense-supply-chain hosts

Workarounds

  • Restrict or monitor execution of the Deno runtime and unsanctioned Python interpreters in enterprise environments
  • Apply application allowlisting/code-signing policy enforcement to flag unusually- or newly-signed binaries executing from user-writable paths

Longer-term hardening

  • Deploy behavioral EDR detections for Registry Run Key and Windows Service-based persistence mechanisms
  • Enforce MFA and monitor externally exposed VPN/authentication endpoints for password-spraying patterns
  • Increase monitoring of defense-industrial-base, financial-sector, and aviation-sector supply-chain vendors given continued Iran-aligned targeting tied to the ongoing conflict

Timeline of Iran Conflict Cyber Operations

  • MuddyWater (Seedworm) first assessed as active, per MITRE ATT&CK Group G0069, initially focused on Middle East targets before expanding to telecommunications, government, defense, and energy sectors globally.
  • CISA, FBI, US Cyber Command CNMF, and UK NCSC issue joint advisory AA22-055A officially attributing MuddyWater activity to a subordinate element of Iran's Ministry of Intelligence and Security (MOIS).
  • Seedworm/MuddyWater intrusion activity begins against a U.S. bank, a U.S. airport, U.S. and Canadian non-profits, and the Israeli operations of a U.S. defense/aerospace software supplier; the actor already had a presence on these networks prior to the outbreak of hostilities.
  • The U.S. and Israel launch a coordinated air campaign of nearly 900 strikes against Iranian military, air-defense, nuclear, and leadership targets, killing Supreme Leader Ayatollah Ali Khamenei along with senior military commanders; Avertium cites this as the trigger for a sustained, measurable rise in Iranian cyber-operations tempo.
  • Researchers observe an attempted data-exfiltration operation using the Rclone utility to copy files from a compromised host to a Wasabi cloud-storage bucket; successful completion of the exfiltration could not be confirmed.
  • Broadcom's Symantec Threat Hunter Team identifies two previously-uncatalogued MuddyWater malware families on victim networks: the Deno-executed JavaScript backdoor Dindoor and the Python backdoor Fakeset, both digitally signed with fraudulent-identity certificates.
  • Iran confirms the death of Khamenei and senior leadership and launches retaliatory missile/drone strikes against U.S. and allied targets across the Middle East.
  • Security.com (Broadcom/Symantec) publishes technical analysis of the Dindoor/Fakeset intrusion set, including file hashes, C2 domains, and Backblaze B2 malware-distribution infrastructure.
  • The Hacker News and SecurityAffairs report on the campaign, corroborating Microsoft ('Trojan:Python/MuddyWater.DB!MTB') and Kaspersky ('Backdoor.Python.MuddyWater.a') detections of Fakeset and linking the code-signing certificates to previously known Stagecomp/Darkcomp malware.
  • Avertium publishes its CTA Campaign Assessment characterizing a sustained, elevated global cyber-risk campaign tied to the Iran conflict, citing active MuddyWater/Seedworm targeting of U.S. banks, airports, and software providers through February-March 2026.

Sources cited for Iran Conflict Cyber Operations

Threats related to Iran Conflict Cyber Operations

Detection coverage for TL-2026-2114

As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2114 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2114

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats