Cybersecurity & Privacy — 2026-03-22
MuddyWater APT Embedded in US Bank and Airport Networks Using New Dindoor Backdoor
Researchers discovered Iranian APT MuddyWater (Seedworm), affiliated with MOIS, embedded in networks of multiple US organizations including banks, airports, and a nonprofit, using a new backdoor called Dindoor. The group also compromised the Israeli arm of a software company. Separately,
Analysis
Part of the 60+ threat group ecosystem documented in Iran Conflict section. MuddyWater's shift from disruptive attacks to persistent intelligence-gathering positions mirrors the pattern CSIS identified in prior INTSUM: cyber warfare shaping the conflict across five domains.
Part of the 60+ threat group ecosystem documented in Iran Conflict section. MuddyWater's shift from disruptive attacks to persistent intelligence-gathering positions mirrors the pattern CSIS identified in prior INTSUM: cyber warfare shaping the conflict across five domains.