Iran Conflict Cyber Operations: MuddyWater (Seedworm) Deploys New Dindoor and Fakeset Backdoors Against US Banks, Airports, Non-Profits, and Defense/Aerospace Software Providers (Feb-Mar 2026) — Threadlinqs Intelligence
As of 2026-03-17, Iran Conflict Cyber Operations: MuddyWater (Seedworm) Deploys New Dindoor and Fakeset Backdoors Against US Banks, Airports, Non-Profits, and Defense/Aerospace Software Providers (Feb-Mar 2026) is a high-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-2114 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Iranian state-aligned actor MuddyWater (Seedworm/TEMP.Zagros/Mango Sandstorm), subordinate to Iran's Ministry of Intelligence and Security, has run a sustained intrusion campaign since early February
Broadcom's Symantec Threat Hunter Team and independent reporting (The Hacker News, SecurityAffairs) document an Iranian state-sponsored intrusion set, attributed to MuddyWater (aka Seedworm, Earth Vetala, MERCURY, Static Kitten, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill), active against multiple U.S. and allied organizations since early February 2026. Victims include a U.S. bank, a U.S. airport, a U.S. non-governmental organization, a Canadian non-profit, and the Israeli operations of a U.S. software company that supplies the defense and aerospace industry. US Cyber Command and CISA (joint advisory AA22-055A) previously and officially attributed MuddyWater to a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), active since at least 2017 with a history of targeting telecommunications, government, defense, and energy-sector organizations for espionage.
The February-March 2026 activity introduces two malware families not previously catalogued in MuddyWater's arsenal. Dindoor is a JavaScript-based backdoor that executes via the Deno secure runtime and was found on the Israeli software-company network, the U.S. bank, and the Canadian non-profit; samples were digitally signed with a certificate issued to "Amy Cherne." Fakeset is a Python-based backdoor deployed against the U.S. airport and non-profit networks, distributed from attacker-controlled Backblaze B2 cloud-storage buckets and signed with certificates ("Amy Cherne," "Donald Gay") that were previously used to sign the related Stagecomp downloader and Darkcomp backdoor -- both malware families independently linked to Seedworm by Google, Microsoft, and Kaspersky. Microsoft detects Fakeset as "Trojan:Python/MuddyWater.DB!MTB" and Kaspersky as "Backdoor.Python.MuddyWater.a." Post-compromise, the actor attempted data exfiltration using the Rclone utility to copy files from a compromised host to a Wasabi cloud-storage bucket, though successful exfiltration could not be confirmed.
Avertium's parallel Cyber Threat Analysis (CTA) assessment, synthesizing reporting from Microsoft DTI, Google GTIG, Unit 42, SentinelOne, Recorded Future, Check Point, Broadcom/Symantec, and CISA/FBI/NSA/DC3, characterizes this as one strand of a measurably elevated, sustained Iranian cyber-operations campaign that accelerated after the February 28, 2026 coordinated U.S.-Israeli military strikes on Iran (which killed Iran's Supreme Leader Ali Khamenei along with senior military leadership). Avertium's broader TTP profile for this campaign cycle -- spear phishing with geopolitical lures, trusted-document/macro abuse, exploitation of unpatched edge devices (VPN/web-facing services), PowerShell-based execution, registry and service-based persistence, encrypted HTTP/S C2 over legitimate cloud/CDN infrastructure, credential harvesting/browser data theft, and network discovery/lateral movement staging -- is consistent with, and corroborated by, the concrete Dindoor/Fakeset intrusion set. Avertium's outlook warns of a three-phase escalation culminating in potential destructive operations against critical infrastructure (energy, utilities, telecom, transportation, healthcare) if the conflict continues. No CVEs are cited by either the Avertium assessment or the Dindoor/Fakeset reporting; this is a TTP- and malware-driven intrusion campaign rather than a single-vulnerability exploit chain.
Target sectors: banking-finance, aviation-transportation, defense-aerospace, non-profit-ngo, technology-software
Target regions: united states of america, canada, israel
Timeline
- MuddyWater (Seedworm) first assessed as active, per MITRE ATT&CK Group G0069, initially focused on Middle East targets before expanding to telecommunications, government, defense, and energy sectors globally.
- CISA, FBI, US Cyber Command CNMF, and UK NCSC issue joint advisory AA22-055A officially attributing MuddyWater activity to a subordinate element of Iran's Ministry of Intelligence and Security (MOIS).
- Seedworm/MuddyWater intrusion activity begins against a U.S. bank, a U.S. airport, U.S. and Canadian non-profits, and the Israeli operations of a U.S. defense/aerospace software supplier; the actor already had a presence on these networks prior to the outbreak of hostilities.
- The U.S. and Israel launch a coordinated air campaign of nearly 900 strikes against Iranian military, air-defense, nuclear, and leadership targets, killing Supreme Leader Ayatollah Ali Khamenei along with senior military commanders; Avertium cites this as the trigger for a sustained, measurable rise in Iranian cyber-operations tempo.
- Iran confirms the death of Khamenei and senior leadership and launches retaliatory missile/drone strikes against U.S. and allied targets across the Middle East.
- Broadcom's Symantec Threat Hunter Team identifies two previously-uncatalogued MuddyWater malware families on victim networks: the Deno-executed JavaScript backdoor Dindoor and the Python backdoor Fakeset, both digitally signed with fraudulent-identity certificates.
- Researchers observe an attempted data-exfiltration operation using the Rclone utility to copy files from a compromised host to a Wasabi cloud-storage bucket; successful completion of the exfiltration could not be confirmed.
- Security.com (Broadcom/Symantec) publishes technical analysis of the Dindoor/Fakeset intrusion set, including file hashes, C2 domains, and Backblaze B2 malware-distribution infrastructure.
- The Hacker News and SecurityAffairs report on the campaign, corroborating Microsoft ('Trojan:Python/MuddyWater.DB!MTB') and Kaspersky ('Backdoor.Python.MuddyWater.a') detections of Fakeset and linking the code-signing certificates to previously known Stagecomp/Darkcomp malware.
- Avertium publishes its CTA Campaign Assessment characterizing a sustained, elevated global cyber-risk campaign tied to the Iran conflict, citing active MuddyWater/Seedworm targeting of U.S. banks, airports, and software providers through February-March 2026.
References
- CTA Campaign Assessment: The Iran Conflict - Global Cyber Operations Risk
- Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company
- Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
- Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
- MuddyWater, Earth Vetala, MERCURY, Static Kitten, Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, MuddyKrill, Group G0069
- Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks (AA22-055A)
- Iran's supreme leader, Ayatollah Ali Khamenei, has been killed
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, T1566, T1190, T1059, T1547, T1543, T1553, T1090, T1555, T1087, T1005