Threats Feed
- Public
Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft
In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.
read more about Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft - Public
False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand
In early 2026, the Iranian state-sponsored APT MuddyWater executed a sophisticated false-flag operation masquerading as a Chaos ransomware attack. Primarily targeting the United States, Israel, and MENA organizations—specifically within the construction, manufacturing, and business services sectors—the group bypassed traditional encryption. Instead, they focused on data exfiltration and long-term espionage. Initial access was achieved via Microsoft Teams social engineering, enabling interactive credential harvesting and MFA manipulation. Attackers established persistence using legitimate remote access tools like DWAgent alongside a custom trojanized WebView2 RAT. Analysis of C2 infrastructure and an MOIS-linked code-signing certificate confirmed the attribution. This hybrid intrusion highlights how state actors increasingly leverage cybercriminal RaaS branding to obscure intelligence-gathering operations.
read more about False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand - Public
Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records
An Iranian-nexus threat actor targeted 12 Omani government ministries, with a primary focus on the Ministry of Justice and Legal Affairs. Utilizing an exposed UAE-based virtual private server, the operator inadvertently revealed their entire operational toolkit, command-and-control infrastructure, and stolen data. The campaign heavily targeted Oman's government, judicial, law enforcement, and administrative sectors to extract citizen identity data, immigration details, and judicial records. The attackers achieved access via ProxyShell and DotNetNuke vulnerabilities, deploying custom webshells and tools like GodPotato for persistent access and privilege escalation. Ultimately, the operation successfully exfiltrated over 26,000 citizen records and critical system registry hives.
read more about Iranian Threat Actors Breach 12 Omani Ministries, Exposing 26,000 Records - Public
DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities
DinDoor, a modular Tsundere botnet variant linked to state-sponsored actors like MuddyWater and cybercrime clusters, exploits the Deno runtime to execute obfuscated JavaScript, effectively bypassing traditional endpoint detections. Delivered via deceptive MSI files, recent campaigns have targeted U.S. organizations and the Russian financial services sector. Upon execution, the malware binds a local port as a mutex, aggressively fingerprints the victim’s hardware, and communicates with a multi-tenant command and control (C2) infrastructure, notably serialmenot[.]com. By analyzing unique Caddy proxy HTTP response headers, researchers identified 20 active C2 servers. Ultimately, DinDoor demonstrates how threat actors increasingly abuse trusted, signed runtimes and shared backend platforms to conceal their operations.
read more about DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities - Public
MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization
Oasis Security analyzed a multi-stage campaign attributed with medium-to-high confidence to MuddyWater, targeting critical infrastructure organizations across the Middle East — primarily Egypt, Israel, and the UAE — as well as Portugal and India. The operation began with large-scale automated reconnaissance, scanning more than 12,000 internet-exposed systems for five newly disclosed vulnerabilities affecting web applications, email servers, IT management platforms, and workflow automation tools. Following this broad scanning phase, the actor shifted to selective, high-value targeting: brute-forcing Outlook Web Access (OWA) credentials using custom tooling and multi-threaded frameworks such as Patator, with confirmed credential harvesting against organizations in Egypt, Israel, and the UAE. A modular, multi-protocol command-and-control (C2) infrastructure hosted in the Netherlands was used to manage compromised hosts, leveraging TCP, UDP, and HTTP channels with AES-encrypted communications — patterns consistent with the ArenaC2 framework previously associated with MuddyWater. The campaign resulted in confirmed exfiltration of sensitive data from an Egyptian aviation organization, including passport and visa records, payroll data, credit card information, and internal corporate documents. Approximately 200 files were staged in attacker-controlled directories prior to exfiltration, indicating structured data collection. The operation's timing — beginning in early February 2026, ahead of escalating regional tensions — suggests alignment with broader Iranian strategic intelligence objectives.
read more about MuddyWater-Linked Campaign Targets Middle Eastern Critical Infrastructure via Novel C2 and Vulnerability Weaponization - Public
MuddyWater's Operation Olalampo: Uncovering C2 Infrastructure and Telegram Bot Utilization in MENA Targets
The APT group MuddyWater recently launched "Operation Olalampo," targeting organizations and individuals primarily across the MENA region amidst ongoing geopolitical tensions. In this campaign, the threat actors deployed newly developed malware variants and utilized Telegram bots for Command and Control (C&C) operations. A deep dive into the campaign's infrastructure revealed the use of recently registered, Namecheap-administered domains localized in Iceland, routing through US-geolocated IP addresses. Further DNS and threat intelligence analysis uncovered a vast network of over 2,500 connected domains linked to a single registrant email, along with active communications originating from ten potential victim IP addresses.
read more about MuddyWater's Operation Olalampo: Uncovering C2 Infrastructure and Telegram Bot Utilization in MENA Targets - Public
MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.
read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage - Public
MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.
read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage - Public
MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.
read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage - Public
MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage
Iranian state-sponsored threat actor MuddyWater has shifted from custom tooling to utilizing the Russian-developed TAG-150 CastleRAT Malware-as-a-Service (MaaS) platform. This strategic capability upgrade equips the group with advanced features like Hidden VNC, Chrome cookie decryption, and a novel blockchain-based command and control agent named "ChainShell." Recent campaigns leveraged fraudulently obtained code-signing certificates and steganography to deploy these tools against targets in Israel, the USA, and the UK. MuddyWater's operations primarily focus on the defence, aerospace, energy, telecommunications, and government sectors. By adopting commercial cybercriminal infrastructure, MuddyWater complicates initial attribution efforts and significantly enhances their espionage operations with highly resilient, off-the-shelf capabilities.
read more about MuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage - Public
HTTP_VIP Malware Profile: System Reconnaissance and RMM Payload Delivery
HTTP_VIP is a downloader malware attributed to the Iranian state-aligned threat actor MuddyWater. Analyzed during the early-2026 campaign dubbed "Operation Olalampo," this tool functions primarily to establish a foothold on compromised systems. It executes system reconnaissance while employing virtualization and sandbox evasion techniques to bypass defensive analysis. Following successful execution, HTTP_VIP connects to its command and control infrastructure to retrieve secondary payloads. Notably, the threat actors utilize this downloader to deploy legitimate remote monitoring and management (RMM) software, specifically AnyDesk. The deployment of AnyDesk facilitates persistent remote access and control over the victim environments, blending malicious activity with standard administrative tools.
read more about HTTP_VIP Malware Profile: System Reconnaissance and RMM Payload Delivery - Public
Boggy Serpens Evolves Tactics: Hijacked Accounts and AI-Enhanced Malware Targeting Critical Infrastructure
Iranian state-sponsored actor Boggy Serpens has escalated cyberespionage campaigns against energy, maritime, finance, aviation, and diplomatic sectors across the Middle East, Europe, Asia, and South America, notably targeting Israel, the UAE, and Turkmenistan. By hijacking trusted corporate and government email accounts, the group bypasses perimeter defenses to deliver highly tailored spear-phishing lures. Recent operations reveal a strategic shift toward stealth and long-term persistence. The group has modernized its toolkit using AI-assisted development, deploying sophisticated custom implants like the Rust-based BlackBeard backdoor, UDPGangster, Nuso, and LampoRAT. To evade detection, Boggy Serpens utilizes evasive C2 mechanisms, including Telegram API abuse, customized UDP traffic, and HTTP status code triggers, cementing its status as a highly adaptable and formidable threat.
read more about Boggy Serpens Evolves Tactics: Hijacked Accounts and AI-Enhanced Malware Targeting Critical Infrastructure - Public
Iranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations
Iranian Ministry of Intelligence and Security (MOIS)-linked threat actors, such as Void Manticore and MuddyWater, are actively integrating cybercriminal tools and affiliate networks into their state-sponsored operations. Moving beyond merely using cybercrime as a cover for deniability, these groups are leveraging commercial infostealers like Rhadamanthys, malware-as-a-service networks like CastleLoader, and the Qilin ransomware-as-a-service (RaaS) to enhance their operational reach and obfuscate attribution. Recent campaigns have targeted government and private sectors, including telecommunications, defense, energy, and medical facilities—across the Middle East, Israel, Albania, and the United States. Notably, these operations have utilized ransomware branding to execute destructive and extortion attacks against Israeli hospitals, fulfilling strategic state objectives through the criminal ecosystem.
read more about Iranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations - Public
MuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs
Huntress researchers have detailed a complete attack chain attributed to the Iranian-linked APT MuddyWater, targeting an Israeli company. The intrusion began with initial access via an RDP login, followed by extensive interactive network and Active Directory reconnaissance. The threat actor demonstrated hands-on-keyboard activity, evidenced by typographical errors during command execution. To establish persistent access and bypass network controls, the attackers utilized the native Windows OpenSSH client to create reverse SSH tunnels. Subsequently, they deployed a malicious payload via DLL side-loading, leveraging the legitimate Fortemedia application (FMAPP.exe) to execute a malicious DLL (FMAPP.dll) for command-and-control communications.
read more about MuddyWater APT Intrusion Analysis: SSH Tunnels and Malicious FMAPP DLLs - Public
Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors
The Iranian APT group Seedworm has targeted multiple organizations across the U.S., Canada, and Israel since February 2026. Leveraging custom malware, the threat actors compromised networks within the financial, aviation, software, defense, and non-profit sectors. Attackers deployed a novel JavaScript/TypeScript backdoor named Dindoor, alongside a Python-based backdoor called Fakeset. To evade detection, the group signed their payloads with digital certificates issued to "Amy Cherne" and "Donald Gay." Additionally, the attackers utilized legitimate cloud services, including Backblaze for staging and Rclone for attempted data exfiltration to Wasabi buckets. Given Seedworm’s affiliation with the Iranian Ministry of Intelligence and Security, these intrusions pose a significant espionage threat amidst current geopolitical conflicts.
read more about Iranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure - Public
Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure
Amid escalating geopolitical tensions, Iranian state-aligned and hacktivist threat groups, including MuddyWater, VoidManticore, APT42, APT35, and Infy, are actively pre-positioning infrastructure for cyber operations. By analyzing ASN patterns, TLS fingerprints, and hosting clusters, defenders can proactively track these adversaries. The groups deploy a mix of custom backdoors, public malware, and Cloudflare-fronted C2 servers to obscure their origins. Campaigns utilize spear-phishing, compromised government mailboxes, and modular scripts to target energy, financial, government, defense, and critical infrastructure sectors. Geographically, these operations focus heavily on the U.S., Israel, the MENA region, Oman, and the UAE, alongside targeting Iranian dissidents and global defense personnel.
read more about Unmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure