Threats Feed
- Public
Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft
In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.
read more about Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft - Public
Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft
In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.
read more about Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft - Public
Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft
In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.
read more about Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft - Public
False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand
In early 2026, the Iranian state-sponsored APT MuddyWater executed a sophisticated false-flag operation masquerading as a Chaos ransomware attack. Primarily targeting the United States, Israel, and MENA organizations—specifically within the construction, manufacturing, and business services sectors—the group bypassed traditional encryption. Instead, they focused on data exfiltration and long-term espionage. Initial access was achieved via Microsoft Teams social engineering, enabling interactive credential harvesting and MFA manipulation. Attackers established persistence using legitimate remote access tools like DWAgent alongside a custom trojanized WebView2 RAT. Analysis of C2 infrastructure and an MOIS-linked code-signing certificate confirmed the attribution. This hybrid intrusion highlights how state actors increasingly leverage cybercriminal RaaS branding to obscure intelligence-gathering operations.
read more about False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand - Public
DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities
DinDoor, a modular Tsundere botnet variant linked to state-sponsored actors like MuddyWater and cybercrime clusters, exploits the Deno runtime to execute obfuscated JavaScript, effectively bypassing traditional endpoint detections. Delivered via deceptive MSI files, recent campaigns have targeted U.S. organizations and the Russian financial services sector. Upon execution, the malware binds a local port as a mutex, aggressively fingerprints the victim’s hardware, and communicates with a multi-tenant command and control (C2) infrastructure, notably serialmenot[.]com. By analyzing unique Caddy proxy HTTP response headers, researchers identified 20 active C2 servers. Ultimately, DinDoor demonstrates how threat actors increasingly abuse trusted, signed runtimes and shared backend platforms to conceal their operations.
read more about DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities - Public
MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.
read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage - Public
Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors
The Iranian APT group Seedworm has targeted multiple organizations across the U.S., Canada, and Israel since February 2026. Leveraging custom malware, the threat actors compromised networks within the financial, aviation, software, defense, and non-profit sectors. Attackers deployed a novel JavaScript/TypeScript backdoor named Dindoor, alongside a Python-based backdoor called Fakeset. To evade detection, the group signed their payloads with digital certificates issued to "Amy Cherne" and "Donald Gay." Additionally, the attackers utilized legitimate cloud services, including Backblaze for staging and Rclone for attempted data exfiltration to Wasabi buckets. Given Seedworm’s affiliation with the Iranian Ministry of Intelligence and Security, these intrusions pose a significant espionage threat amidst current geopolitical conflicts.
read more about Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors - Public
Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors
The Iranian APT group Seedworm has targeted multiple organizations across the U.S., Canada, and Israel since February 2026. Leveraging custom malware, the threat actors compromised networks within the financial, aviation, software, defense, and non-profit sectors. Attackers deployed a novel JavaScript/TypeScript backdoor named Dindoor, alongside a Python-based backdoor called Fakeset. To evade detection, the group signed their payloads with digital certificates issued to "Amy Cherne" and "Donald Gay." Additionally, the attackers utilized legitimate cloud services, including Backblaze for staging and Rclone for attempted data exfiltration to Wasabi buckets. Given Seedworm’s affiliation with the Iranian Ministry of Intelligence and Security, these intrusions pose a significant espionage threat amidst current geopolitical conflicts.
read more about Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors - Public
Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors
The Iranian APT group Seedworm has targeted multiple organizations across the U.S., Canada, and Israel since February 2026. Leveraging custom malware, the threat actors compromised networks within the financial, aviation, software, defense, and non-profit sectors. Attackers deployed a novel JavaScript/TypeScript backdoor named Dindoor, alongside a Python-based backdoor called Fakeset. To evade detection, the group signed their payloads with digital certificates issued to "Amy Cherne" and "Donald Gay." Additionally, the attackers utilized legitimate cloud services, including Backblaze for staging and Rclone for attempted data exfiltration to Wasabi buckets. Given Seedworm’s affiliation with the Iranian Ministry of Intelligence and Security, these intrusions pose a significant espionage threat amidst current geopolitical conflicts.
read more about Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors - Public
Avast-Themed Phishing Campaign Targets Israeli Businesses with ScreenConnect RAT
A phishing campaign impersonating Avast targeted Israeli individuals and businesses—likely in the real estate and commercial sectors—through fraudulent antivirus receipts containing malware download links. The attack used multiple URL redirections and GitHub for payload delivery, culminating in the stealthy installation of the legitimate remote access tool ScreenConnect. Once installed, the malware achieved persistence via Windows services, modified authentication packages to access credentials, and established encrypted command and control connections. Evidence suggests similarities with tactics used by the MuddyWater APT group, though attribution remains inconclusive. The campaign’s infrastructure and system language checks confirm its Israeli focus.
read more about Avast-Themed Phishing Campaign Targets Israeli Businesses with ScreenConnect RAT - Public
Seedworm Leverages Atera Agent in Sophisticated Spear-Phishing Scheme
Seedworm, also known as MuddyWater, is exploiting the Atera Agent, a legitimate remote monitoring and management (RMM) tool, in its spear-phishing campaigns. The group uses Atera’s 30-day free trial offers to register agents with compromised email accounts, enabling them to access targeted systems remotely without needing their own command-and-control infrastructure. These capabilities include file upload/download, interactive shell access, and AI-powered command assistance through Atera’s web UI. Seedworm distributes the malicious RMM installers hosted on free file platforms via spear-phishing emails, though the specific targeted countries and sectors are not mentioned in the report.
read more about Seedworm Leverages Atera Agent in Sophisticated Spear-Phishing Scheme - Public
MuddyWater Masquerades as Hacktivists in Combined Extortion and Disinformation Campaign
Iranian state-sponsored threat actor MuddyWater has aggressively targeted Israeli organizations in the finance, academia, and government sectors since late 2022. Operating under the guise of a hacktivist persona named "Darkbit," the group conducted a combined destructive ransomware and disinformation campaign against an academic institution in February 2023. Gaining access via phishing and exploiting vulnerabilities like Log4j, the attackers deployed custom Go-based ransomware alongside remote access tools like SyncroRAT and PowerShower. The operation involved both computer network exploitation, stealing 4TB of data—and computer network attacks, disrupting critical systems while demanding an exorbitant 80 Bitcoin ransom to mask their state-backed espionage and psychological objectives.
read more about MuddyWater Masquerades as Hacktivists in Combined Extortion and Disinformation Campaign - Public
Seedworm Group Suspected in Sweeping Espionage Campaign Across Telecom and IT Services
An espionage campaign tentatively linked to the Iranian-backed Seedworm group has been using compromised organizations as stepping stones to additional victims or targets that may have been compromised solely to perform supply-chain-type attacks on other organizations. The attackers primarily used legitimate tools, publicly available malware, and living-off-the-land tactics, with a significant interest in Exchange Servers. While the ultimate end goal remains unknown, the focus on telecom operators suggests the attackers are gathering intelligence on the sector, potentially pivoting into communications surveillance.
read more about Seedworm Group Suspected in Sweeping Espionage Campaign Across Telecom and IT Services - Public
Seedworm's Rising Activity: Middle East Targets and PowGoop Tool Connections
The espionage group Seedworm (aka MuddyWater) has been actively targeting government organizations, telecoms, and computer services sectors across the Middle East, including Iraq, Turkey, Kuwait, the United Arab Emirates, Georgia, Afghanistan, Israel, Azerbaijan, Cambodia, and Vietnam. Seedworm's recent activities, linked to the PowGoop tool, involve PowerShell usage, credential dumping, and DLL side-loading. The group establishes connections to its infrastructure using Secure Sockets Funneling and Chisel while deploying PowGoop through remote execution tools. The connection between PowGoop and Seedworm remains tentative, suggesting potential retooling.
read more about Seedworm's Rising Activity: Middle East Targets and PowGoop Tool Connections - Public
Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security
In a series of espionage-focused campaigns, the Cobalt Ulster threat group, linked to the Iranian government, targeted governmental and intergovernmental organizations across Turkey, Jordan, Iraq, Georgia, and Azerbaijan from mid-2019 to mid-January 2020. These attacks primarily involved spearphishing with malicious attachments and links to compromised websites. The group used various techniques, including obfuscated macros in Excel files, VBScript, and PowerShell scripts for initial access and persistence. The campaigns featured sophisticated methods like DNS tunneling for command and control, and the use of tools for credential harvesting and establishing reverse SSL tunnels, indicating a high level of technical proficiency and strategic planning.
read more about Cobalt Ulster Spearphishing Operations: A Continued Threat to Governmental Security - Public
MuddyWater’s Advanced Tactics Exploit CVE-2017-0199 in Global Campaigns
The Iranian APT group MuddyWater has expanded its tactics, targeting government, telecommunications and military sectors in countries such as Tajikistan, Pakistan and Iraq. New campaigns include decoy documents exploiting CVE-2017-0199 and malicious VBA macros, with second-stage payloads downloaded from compromised servers. Primary targets have impersonated entities in the region surrounding Iran, including Iraqi and Pakistani organisations. The group also uses RATs for process detection, using obfuscation techniques such as Base64 encoding and JavaScript layers. Compromised servers in Pakistan and China facilitated these operations, demonstrating MuddyWater's sophisticated arsenal and focus on espionage.
read more about MuddyWater’s Advanced Tactics Exploit CVE-2017-0199 in Global Campaigns - Public
SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants
The provided report outlines the activities of a malware campaign leveraging the SeedWorm backdoor, specifically through variants of a program named LisfonService. These variants were developed and deployed using PowerShell to download and execute a malicious program, 'muddy', across targeted systems. Notably, the campaign utilizes filenames such as svchosts.exe and lisfon.exe to obscure its malicious intent.
read more about SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants - Public
Seedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors
Seedworm has compromised more than 130 victims across 30 organizations since September 2018. The group targets primarily the Middle East, Europe, and North America, focusing on government agencies, oil and gas companies, NGOs, telecoms, and IT firms. Seedworm uses tools such as Powermud, Powemuddy, and PowerShell scripts and has updated its tactics to avoid detection. The main targeted sectors include telecommunications, IT services, oil and gas, universities, and embassies. The group is known for its speed and agility in obtaining actionable intelligence from targeted organizations.
read more about Seedworm's Persistent Cyber Campaigns: Intelligence Gathering across Multiple Sectors