Cybersecurity & Privacy — 2026-03-22

MuddyWater APT Embedded in US Bank and Airport Networks Using New Dindoor Backdoor

Researchers discovered Iranian APT MuddyWater (Seedworm), affiliated with MOIS, embedded in networks of multiple US organizations including banks, airports, and a nonprofit, using a new backdoor called Dindoor. The group also compromised the Israeli arm of a software company. Separately, Handala hacktivist group claimed to have breached Sharjah National Oil Corporation and Israel Opportunity Energy, exfiltrating over 1.3TB of sensitive data including oil contracts and financial records. The operations demonstrate Iran's shift from disruptive attacks to persistent intelligence-gathering positions inside Western critical infrastructure.

Analysis
Part of the 60+ threat group ecosystem documented in Iran Conflict section. MuddyWater's shift from disruptive attacks to persistent intelligence-gathering positions mirrors the pattern CSIS identified in prior INTSUM: cyber warfare shaping the conflict across five domains.
2 sources
  1. Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor - The Hacker News
  2. Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company - Security.com

View in full brief →

UNCLASSIFIED // OPEN SOURCE