Iranian Hackers Target US Infrastructure: A Looming Cyber Threat
A sophisticated Iranian cyber operation, linked to the Iranian Ministry of Intelligence and Security (MOIS) and known as MuddyWater (also Seedworm and Static Kitten), has infiltrated networks belonging to a US bank, airport, software company, and non-governmental organizations in both the US and Canada. This activity, detected since early February 2026, coincides with heightened geopolitical tensions following military strikes between the US, Israel, and Iran, raising concerns about potential escalation in the cyber domain.
New Backdoors and Tactics Revealed
Security researchers at Symantec and Carbon Black uncovered the intrusions after receiving indicators of compromise. The attackers deployed at least two distinct backdoors: Dindoor, found on the networks of an Israeli software company, a US bank, and a Canadian nonprofit, and Fakeset, discovered on the US airport and a US nonprofit. Dindoor uniquely leverages Deno, a secure runtime for JavaScript and TypeScript, for execution. Both backdoors were signed with certificates attributed to individuals named “Amy Cherne” and “Donald Gay,” with the latter previously linked to MuddyWater malware.
Dindoor: A Novel Approach to Backdoor Implementation
The use of Deno in Dindoor represents a noteworthy tactic. Deno’s security features are being subverted for malicious purposes, highlighting the evolving sophistication of threat actors. The attempt to exfiltrate data from the software company using Rclone to a Wasabi cloud storage bucket suggests a focus on intelligence gathering.
Israel as a Primary Target
The Israeli operation of the compromised software company, which supplies technology to the defense and aerospace industries, appears to be a primary focus of the attacks. This aligns with previous Iranian cyber activity targeting Israel, and raises concerns about potential espionage aimed at acquiring sensitive information or disrupting critical infrastructure.
The Broader Context: Iranian Cyber Capabilities
MuddyWater has been active since at least 2018, carrying out cyber campaigns on behalf of the Iranian MOIS. The group frequently employs phishing emails and exploits vulnerabilities in public-facing applications to gain initial access to networks. The reuse of certificate signatures across multiple intrusions confirms the attribution to MuddyWater.
Potential for Escalation and Future Trends
The current situation presents a heightened risk of cyberattacks. Having established a foothold in US and Israeli networks before the recent hostilities began, MuddyWater is well-positioned to launch disruptive attacks. While current activity points towards intelligence gathering, the group could easily pivot to disruption, particularly given Iran’s history of both intelligence gathering and disruptive cyber operations.
Recent observations indicate a broader increase in cyber activity originating from Iran, including exploitation attempts targeting internet-connected surveillance cameras in Israel and other Middle Eastern countries, as well as general spying expeditions and DDoS attacks. The lack of disruptive attacks *so far* does not diminish the threat.
FAQ
- What is MuddyWater? MuddyWater is an Iranian advanced persistent threat (APT) group linked to the Iranian Ministry of Intelligence and Security (MOIS).
- What types of organizations are being targeted? US and Canadian banks, airports, software companies, and non-governmental organizations have been targeted.
- What is Dindoor? Dindoor is a newly discovered backdoor used by MuddyWater, notable for leveraging the Deno runtime environment.
- Is data being stolen? Attempts to exfiltrate data have been observed, suggesting intelligence gathering is a primary motive.
- What is the risk of future attacks? The risk of disruptive cyberattacks is elevated, as MuddyWater already has a presence on compromised networks.
Pro Tip: Regularly update software and security systems, implement multi-factor authentication, and educate employees about phishing threats to mitigate the risk of cyberattacks.
Did you know? The certificates used to sign the backdoors were previously associated with other MuddyWater malware, strengthening the attribution to this Iranian threat actor.
Stay informed about the latest cybersecurity threats and best practices. Explore our other articles on threat intelligence and network security to learn how to protect your organization from evolving cyber risks. Read more here.
Worth a look