Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Target U.S. Networks with New Malware

Iranian Hackers Target U.S. Networks with New Malware

Posted on March 6, 2026 By CWS

Recent investigations by cybersecurity experts from Broadcom’s Symantec and Carbon Black have uncovered a significant cyber threat stemming from an Iranian-linked hacking group. This group has been identified as infiltrating several U.S. networks, including banks, airports, and the Israeli branch of a prominent software company.

Details of the Cyber Campaign

The hacking group, known as MuddyWater or Seedworm, is believed to operate under the Iranian Ministry of Intelligence and Security. Their activities reportedly began in early February and have escalated following military actions involving the U.S. and Israel. The software company targeted by these attacks supplies to defense and aerospace sectors, making its Israeli operations a primary focus.

The group has deployed a newly discovered backdoor, named Dindoor, which utilizes the Deno JavaScript runtime. Additionally, they attempted data exfiltration using the Rclone utility to the Wasabi cloud storage but the success of these attempts remains unclear.

Additional Threats Identified

Further analysis revealed the presence of a Python-based backdoor, Fakeset, within the networks of a U.S. airport and a non-profit organization. This malware was downloaded from servers associated with Backblaze, a U.S.-based cloud storage provider. Notably, the digital certificate used to authenticate Fakeset also signed other malware linked to MuddyWater, indicating a consistent threat actor.

The Iranian threat actors have honed their capabilities in recent years, enhancing their malware and employing sophisticated social engineering tactics, including spear-phishing and honeytrap operations to infiltrate target networks.

Implications of Ongoing Cyber Attacks

The findings come amid escalating tensions in the Middle East, with cyber attacks intensifying as a form of retaliation. According to Check Point, pro-Palestinian hacktivists have exploited vulnerabilities in IP cameras across Israel and the Gulf region, demonstrating the broader scope of these cyber operations.

In light of the ongoing conflict, the Canadian Centre for Cyber Security has issued a warning about potential Iranian cyber attacks on critical infrastructure. Other key developments include attacks on Tehran’s traffic camera network and Amazon’s data center in Bahrain.

Strengthening Cybersecurity Measures

Organizations are urged to enhance their cybersecurity defenses in response to these threats. Recommended measures include improving network monitoring, implementing phishing-resistant multi-factor authentication, and ensuring all systems are updated and secured against known vulnerabilities.

As cyber threats continue to evolve, maintaining vigilance and adopting robust security practices is essential for safeguarding critical networks against potential Iranian cyber operations.

The Hacker News Tags:Backdoor, cyber attacks, cyber threats, Cybersecurity, Dindoor, Iranian hackers, Malware, Middle East conflict, MuddyWater, U.S. networks

Post navigation

Previous Post: Exploited Rockwell Vulnerability in ICS Revealed
Next Post: CISA Expands KEV List with iOS Vulnerability Additions

Related Posts

Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale Vercel’s v0 AI Tool Weaponized by Cybercriminals to Rapidly Create Fake Login Pages at Scale The Hacker News
OAuth Risks: The Overlooked Threat to Corporate Security OAuth Risks: The Overlooked Threat to Corporate Security The Hacker News
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability The Hacker News
The Impact of Robotic Process Automation (RPA) on Identity and Access Management The Impact of Robotic Process Automation (RPA) on Identity and Access Management The Hacker News
CISA Identifies Exploited Wing FTP Vulnerability CISA Identifies Exploited Wing FTP Vulnerability The Hacker News
Critical Flaw in LMS Exploited for Cyber Attacks Critical Flaw in LMS Exploited for Cyber Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Opal Security Secures $23M to Enhance AI Identity Governance
  • CISA Flags SolarWinds Vulnerability in Security Alert
  • Hugging Face Vulnerability Risks Remote Code Attacks
  • Smart TVs Used as AI Data Proxies by Free Apps
  • Top Simulated DDoS Testing Tools for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Opal Security Secures $23M to Enhance AI Identity Governance
  • CISA Flags SolarWinds Vulnerability in Security Alert
  • Hugging Face Vulnerability Risks Remote Code Attacks
  • Smart TVs Used as AI Data Proxies by Free Apps
  • Top Simulated DDoS Testing Tools for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark