Campaign
MuddyWater intrusion into U.S. networks and an Israeli software arm
Updated 06.03.2026 17:15
Case score 55
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 55
- Main story score
- 55
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Campaign Lead campaign item describing MuddyWater footholds across multiple U.S. organizations and an Israeli software arm, including Dindoor and attempted Rclone exfiltration. main
Members 1
First seen 06.03.2026 12:23
Latest activity 06.03.2026 17:15
Overview
MuddyWater has established footholds in U.S. banks, airports, a non-profit, and the Israeli arm of a software company, using a **Deno**-based **Dindoor** backdoor and an attempted **Rclone** transfer to a **Wasabi** bucket. The activity was assessed to have started in early February and was seen again after U.S. and Israeli military strikes on Iran, indicating the intrusion set remained active over time.
Available evidence points to persistence and attempted theft, but it does not quantify overall reach or the initial access path. Defender attention should center on **Dindoor**, **Fakeset**, and unusual cloud-storage egress tied to the affected networks.
Latest development
MuddyWater campaign disclosure against U.S. company networks
Broadcom's Symantec and Carbon Black Threat Hunter Team disclosed that MuddyWater (Seedworm), an Iran MOIS-linked group, had embedded itself in several U.S. companies' networks, including banks, airports, a non-profit, and the Israeli arm of a software company. The researchers said the campaign began in early February and included a new Dindoor backdoor built on the Deno JavaScript runtime, plus an attempted Rclone exfiltration to a Wasabi cloud storage bucket from the software company arm.
MuddyWater has established footholds in U.S. banks, airports, a non-profit, and the Israeli arm of a software company. The activity was assessed to have started in early February and was seen again after U.S. and Israeli military strikes on Iran. Broadcom's Symantec and Carbon Black Threat Hunter Team tied the operation to MuddyWater, also known as Seedworm, and described it as a broad access campaign rather than a single isolated compromise.
The operators used a previously unknown backdoor called Dindoor, which executes through the Deno JavaScript runtime, and attempted to move data with Rclone to a Wasabi cloud bucket from the software company arm. Investigators also found a separate Python backdoor called Fakeset in other networks, with certificate reuse linking it to earlier MuddyWater tooling such as Stagecomp and Darkcomp. Available evidence does not quantify the full reach, initial access method, or downstream impact in each environment, but it does show persistence and attempted exfiltration across multiple victims.
Signals
CVEs/products
Geographic context
Status
Threat context
Threat actor context
7 listedMalware & tooling context
9 families · 1 toolsTechnical intelligence
Existing Case dataMember happenings
Campaign
MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
Objective
Espionage
Campaign
Active
Campaign
MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
Objective
Espionage
Campaign
Active