HomeSecurityMuddyWater invades US networks with new backdoor

MuddyWater Invades US Networks with New Backdoor

Iranian hackers MuddyWater have infiltrated the networks of several American companies, including banks, airports and non-profit organizations, using a new backdoor called Dindoor . According to new research from Symantec and Broadcom ’s Carbon Black Threat Hunter Team , the state-sponsored group has expanded its operations beyond its traditional Middle Eastern target.

MuddyWater backdoor Dindoor

MuddyWater , also known as Seedworm , is affiliated with the Iranian Ministry of Intelligence and Security ( MOIS ) . The group has been active since at least 2017 and has targeted government, telecommunications, defense, and energy organizations in multiple countries. U.S. Cyber ​​Command officially linked MuddyWater to MOIS in January 2022 , marking the first official U.S. government recognition.

The current campaign is estimated to have begun in early February 2026, with recent activity detected following US and Israeli military attacks on Iran. Targets include a software company that supplies the defense and aerospace industries, with the Israeli division appearing to be the focus of the activity.

See also: MuddyWater targets Turkey-Israel-Azerbaijan with UDPGangster Backdoor

New Backdoor Dindoor Exploits JavaScript Runtime

The new Dindoor leverages the Deno JavaScript runtime for execution, representing a significant technological advancement in MuddyWater. Attacks targeting the software company, as well as a US bank and a Canadian non-profit organization, have been found to open the way for this previously unknown backdoor. Broadcom also detected an attempt to extract data from the software company using the Rclone to a Wasabi cloud storage bucket, although it is not known whether this attempt was successful.

Additionally, a separate Python called Fakeset was found on the networks of an American airport and a non-profit organization. This backdoor was downloaded from servers owned by Backblaze, an American cloud storage and data backup company. The digital certificate used to sign Fakesethas also been used to sign the Stagecomp and Darkcomp, which were previously also linked to MuddyWater.

Symantec and Carbon Black researchers noted that while this malware was not detected on the targeted networks, the use of the same certificates suggests that Seedworm was behind the activity on the networks of US companies. This tactic of using shared certificates is a hallmark of the group and helps security researchers attribute the attacks.

MuddyWater Iranian hacker group attacks US networks

Evolution of Iranian Cyber ​​Capabilities

Iranian threat actors have become increasingly sophisticated in recent years. Their tools and malware have improved and they have demonstrated strong social engineering capabilities, including spear-phishing campaigns and honeytrap operations used to build relationships with targets of interest (to gain access to accounts or sensitive information).

See also: Operation Olalampo: MuddyWater targets organizations with new malware

In the past 12 months , MuddyWater also launched Operation Olalampo targeting organizations in the MENA region with the GhostFetch and CHAR malware for espionage. In July 2024 , the group expanded to Azerbaijan, Portugal, Turkey, Saudi Arabia, and India using new malware and phishing links embedded in PDFs (to evade security filters).

These findings come amid an escalating military conflict in Iran, causing a barrage of cyber attacks across the digital space. Recent research from Check Point revealed the pro-Palestinian hacktivist group known as Handala Hack (also known as Void Manticore) is routing its operations through Starlink IP ranges to examine externally accessible applications for misconfigurations and weak credentials.

In recent months, various Iran-linked groups, such as Agrius (also known as Agonizing Serpens, Marsthreader , and Pink Sandstorm), have been observed scanning for vulnerable Hikvision and video intercom solutions using known vulnerabilities such as CVE-2017-7921 and CVE-2023-6895. The targeting has intensified following the current Middle East conflict, with exploit attempts against IP cameras increasing in Israel and the Gulf countries.

See also: MuddyWater uses malicious Word documents to distribute RustyWater

spectre malware

Organizations are advised to strengthen cybersecurity, specifically: strengthen monitoring capabilities, limit online exposure, disable remote access to OT systems, enforce phishing-resistant multi-factor authentication (MFA), implement network segmentation, and take offline backups. Finally, they should ensure that all internet-facing applications, VPN gateways, and edge devices are up to date.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS