Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Cyber Attacks Target US Networks, Cameras for Surveillance

Iranian Cyber Attacks Target US Networks, Cameras for Surveillance

Posted on March 17, 2026 By CWS

In early 2026, Iranian cyber operations expanded significantly, with state-affiliated threat groups embedding themselves in US and Canadian networks. Simultaneously, they targeted internet-connected surveillance cameras across the Middle East to gather battlefield intelligence.

Infiltration of US Networks

The Iranian APT group, MuddyWater, linked to Iran’s Ministry of Intelligence and Security, has reportedly been maintaining unauthorized access to various American organizations since February 2026. The sectors affected include banking, aviation, defense supply chains, and non-profit organizations.

Reports from Symantec and Carbon Black exposed this illicit activity, highlighting MuddyWater’s use of undocumented malware to secure persistent access in victim networks. This approach aligns with state-sponsored espionage, focusing on sustained intelligence collection rather than immediate disruption.

Malware Tools and Tactics

PolySwarm analysts have identified several malware families associated with MuddyWater’s attacks on US entities, including Dindoor and Fakeset. The Dindoor backdoor was discovered infiltrating a US software company’s network, which serves defense and aerospace clients, using the Deno runtime for JavaScript and TypeScript to maintain access.

Fakeset, a Python-based backdoor, was detected in the networks of a US airport and a non-profit organization. These tools are engineered to remain undetected, ensuring long-term presence in compromised systems.

Surveillance Camera Exploitation

Beyond network penetration, Iranian infrastructure initiated extensive scanning of internet-connected surveillance cameras from February 28, 2026. Check Point Research documented a surge in exploit attempts targeting Hikvision and Dahua cameras, affecting commercial, government, and municipal setups across the region.

This activity spanned Israel, Qatar, Bahrain, Kuwait, the UAE, Lebanon, and Cyprus, coinciding with regional hostilities, and emphasizes Iran’s strategic use of these devices for real-time intelligence gathering.

The exploitation of surveillance cameras is a deliberate tactic to transform standard security equipment into intelligence platforms. Iranian actors leverage vulnerabilities like CVE-2017-7921 in Hikvision and CVE-2021-33044 in Dahua devices to monitor and assess locations.

Recommendations and Outlook

Organizations using Hikvision or Dahua cameras must apply all available firmware patches, especially those addressing known vulnerabilities. Segmentation of camera systems from core networks, disabling unnecessary remote access, and enforcing strong authentication are vital preventive measures.

For sectors targeted by MuddyWater, vigilance for unusual activities involving Deno runtime, unexpected Python processes, and Rclone traffic is crucial. Digital certificate-based detection and traffic inspection should be integrated into defense strategies to counter these sophisticated threats.

Given the current geopolitical tensions, organizations must prioritize these risks in their incident response strategies to mitigate potential impacts.

Cyber Security News Tags:APT groups, CVE vulnerabilities, Cybersecurity, Dahua, Dindoor, Espionage, Fakeset, Hikvision, Iran, Malware, MuddyWater, Surveillance, US networks

Post navigation

Previous Post: AI Vulnerability Exposed Through Custom Font Attacks
Next Post: AWS Sandbox Vulnerability Exposes Data to Covert Channels

Related Posts

Cl0p Hackers Target Windchill Servers for Data Theft Cl0p Hackers Target Windchill Servers for Data Theft Cyber Security News
Critical Mitigation for Windows BitLocker Security Flaw Critical Mitigation for Windows BitLocker Security Flaw Cyber Security News
Chinese Hackers Breach Oil Sector via Microsoft Exchange Chinese Hackers Breach Oil Sector via Microsoft Exchange Cyber Security News
WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login Cyber Security News
Threat Actors Widely Abuse .COM TLD to Host Credential Phishing Website Threat Actors Widely Abuse .COM TLD to Host Credential Phishing Website Cyber Security News
Microsoft 365 Outage Disrupts North American Admin Access Microsoft 365 Outage Disrupts North American Admin Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark