Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

MuddyWater intrusion into U.S. networks and an Israeli software arm

Updated 06.03.2026 17:15
Case score 55
Members 1 First seen 06.03.2026 12:23 Latest activity 06.03.2026 17:15

Overview

MuddyWater has established footholds in U.S. banks, airports, a non-profit, and the Israeli arm of a software company, using a **Deno**-based **Dindoor** backdoor and an attempted **Rclone** transfer to a **Wasabi** bucket. The activity was assessed to have started in early February and was seen again after U.S. and Israeli military strikes on Iran, indicating the intrusion set remained active over time. Available evidence points to persistence and attempted theft, but it does not quantify overall reach or the initial access path. Defender attention should center on **Dindoor**, **Fakeset**, and unusual cloud-storage egress tied to the affected networks.
Latest development

MuddyWater campaign disclosure against U.S. company networks

Broadcom's Symantec and Carbon Black Threat Hunter Team disclosed that MuddyWater (Seedworm), an Iran MOIS-linked group, had embedded itself in several U.S. companies' networks, including banks, airports, a non-profit, and the Israeli arm of a software company. The researchers said the campaign began in early February and included a new Dindoor backdoor built on the Deno JavaScript runtime, plus an attempted Rclone exfiltration to a Wasabi cloud storage bucket from the software company arm.

Signals

CVEs/products
Geographic context
Status
Threat context

Threat actor context

7 listed

Malware & tooling context

9 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
Updated 06.03.2026 12:23 Lead Contribution 55
Objective Espionage Campaign Active

**MuddyWater (Seedworm)** is running a **state-linked intrusion campaign** that has embedded itself in **U.S. banks, airports, a non-profit, and an Israeli software company arm**, widening risk across multiple sectors. The operation was assessed to have started in **early February** and appears to have intensified after **U.S. and Israeli strikes on Iran**. The campaign matters because it paired **backdoor deployment** with an attempted **data exfiltration** path, indicating potential persistence and theft.