Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

MuddyWater intrusion into U.S. networks and an Israeli software arm

Updated 06.03.2026 17:15
Case score 55
Case score 55 Members 1 Latest activity 06.03.2026 17:15
Members 1 First seen 06.03.2026 12:23 Last seen 06.03.2026 12:23 Updated 06.03.2026 17:15

Overview

MuddyWater has established footholds in U.S. banks, airports, a non-profit, and the Israeli arm of a software company, using a **Deno**-based **Dindoor** backdoor and an attempted **Rclone** transfer to a **Wasabi** bucket. The activity was assessed to have started in early February and was seen again after U.S. and Israeli military strikes on Iran, indicating the intrusion set remained active over time. Available evidence points to persistence and attempted theft, but it does not quantify overall reach or the initial access path. Defender attention should center on **Dindoor**, **Fakeset**, and unusual cloud-storage egress tied to the affected networks.

Signals

5 derived
Victims/regions
Attacker region Iran Victim region United States
Status
Campaign status Active
Threat context
Actor MuddyWater Malware

Malware context

9 families · 1 tools
Tools
NoName057(16)

Member happenings

1 related
Campaign MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
Updated 06.03.2026 12:23 Lead Contribution 55
Objective Espionage Campaign Active

**MuddyWater (Seedworm)** is running a **state-linked intrusion campaign** that has embedded itself in **U.S. banks, airports, a non-profit, and an Israeli software company arm**, widening risk across multiple sectors. The operation was assessed to have started in **early February** and appears to have intensified after **U.S. and Israeli strikes on Iran**. The campaign matters because it paired **backdoor deployment** with an attempted **data exfiltration** path, indicating potential persistence and theft.