Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Cyber Group Targets US Organizations Amid Tensions

Iranian Cyber Group Targets US Organizations Amid Tensions

Posted on March 6, 2026 By CWS

The Iranian advanced persistent threat (APT) group, known as MuddyWater, has successfully breached several US-based organizations, according to recent reports from Broadcom’s Symantec and the Carbon Black threat hunting team. The cyber-attacks have affected a range of sectors, including an aerospace and defense contractor, a US airport, and a bank.

Targeted Entities in the US and Beyond

MuddyWater’s infiltration extends beyond US borders, impacting entities like a software firm operating in Israel and a non-governmental organization (NGO) active in both the US and Canada. These attacks have intensified following recent military actions by the US and Israel against Iran, which have heightened regional tensions.

The compromised software company, which serves the aerospace and defense sectors, has been a significant target due to its operations in Israel. This makes it particularly vulnerable to MuddyWater’s espionage activities.

Deployment of Sophisticated Backdoors

As part of their campaign, MuddyWater introduced a new backdoor termed ‘Dindoor’ into the networks of the targeted software company’s Israeli branch, as well as into the US bank and Canadian NGO. This backdoor carried a certificate attributed to ‘Amy Cherne’. Furthermore, the group attempted to extract sensitive data from these networks.

Additionally, the cybersecurity team identified another backdoor, ‘Fakeset’, developed using Python, which was found in the systems of a US airport and an NGO. This malware, too, was linked to certificates previously used in MuddyWater’s operations.

Ongoing Threat and Security Insights

Although the malicious activities have been temporarily disrupted, the potential risk remains high. Symantec and Carbon Black warn that other organizations could still be susceptible to similar breaches. MuddyWater, also known by aliases such as Mango Sandstorm and Seedworm, is associated with Iran’s Ministry of Intelligence and Security.

Active since 2017, the group is notorious for targeting Middle Eastern entities and has recently escalated its cyber warfare capabilities. Notably, last year, Amazon documented the APT’s involvement in hacking live CCTV streams in Jerusalem to support missile attacks.

The cybersecurity landscape continues to evolve, with state-sponsored actors like MuddyWater posing significant challenges. Organizations must remain vigilant and strengthen their defenses against sophisticated cyber threats.

Security Week News Tags:APT, Backdoor, cyber threats, Cybersecurity, data breach, Iranian hackers, IT security, MuddyWater, network security, US organizations

Post navigation

Previous Post: Critical Security Flaws in Hikvision and Rockwell Products
Next Post: Phishing Emails Target iOS Users with Fake AI Apps

Related Posts

Gambit Security Secures M for AI Cyber Resilience Gambit Security Secures $61M for AI Cyber Resilience Security Week News
Zscaler to Acquire MDR Specialist Red Canary Zscaler to Acquire MDR Specialist Red Canary Security Week News
Gambit Security Secures M for AI Cyber Resilience Backslash Secures $19M to Enhance Vibe Coding Protection Security Week News
United Natural Foods Projects Up to 0M Sales Hit from June Cyberattack United Natural Foods Projects Up to $400M Sales Hit from June Cyberattack Security Week News
Iranian Hackers Target Defense and Government Officials in Ongoing Campaign Iranian Hackers Target Defense and Government Officials in Ongoing Campaign Security Week News
ServiceNow to Acquire Identity Security Firm Veza in Reported  Billion Deal  ServiceNow to Acquire Identity Security Firm Veza in Reported $1 Billion Deal  Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit
  • PureRAT Malware Utilizes PNG Files for Stealthy Attacks
  • SystemBC Server Uncovers 1,570 Victims in Ransomware Operation
  • AI-Enhanced NGate Malware Targets NFC Payment Apps
  • AI Identity Visibility Lacking in Enterprises, Study Finds

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Over 6000 Apache ActiveMQ Servers Risk CVE-2026-34197 Exploit
  • PureRAT Malware Utilizes PNG Files for Stealthy Attacks
  • SystemBC Server Uncovers 1,570 Victims in Ransomware Operation
  • AI-Enhanced NGate Malware Targets NFC Payment Apps
  • AI Identity Visibility Lacking in Enterprises, Study Finds

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark