Thursday , September 17 2026
Seedworm

Seedworm hackers found inside US bank, airline, tech networks

An Iran-related hacking group (Seedworm) has infiltrated multiple US organizations since early February, heightening fears of potential larger cyber operations linked to rising geopolitical tensions in the Middle East.

New backdoors used by Seedworm

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Researchers from Symantec and Carbon Black have connected the activity to Seedworm (also known as MuddyWater), an Iranian group linked to the Ministry of Intelligence and Security, known for targeting government and critical infrastructure.

According to researchers, suspicious activity linked to Seedworm has been identified on the networks of:

A US bank
A US airport
Non-profit organizations, and
The Israeli operations of a US software company that supplies the defense and aerospace industries.

The activity started in early February 2026 and is still ongoing, with the group using new malware.

  • The Dindoor backdoor, named thus due to its use of Deno, a runtime environment for JavaScript and TypeScript, for executing commands on infected machines
  • A Python-based backdoor called Fakeset.

According to the researchers, Dindoor was digitally signed with a certificate issued to an individual named “Amy Cherne”. Fakeset was also signed, using using certificates attributed to both “Amy Cherne” and “Donald Gay,” the latter of which has previously been associated with the Stagecomp and Darkcomp malware used by the Seedworm APT.

The attackers appear to be spying; they aim to steal data from the software company and upload it to a Wasabi cloud storage bucket using the Rclone tool.

“While it’s not known if the operations of Seedworm are disrupted by the current conflict, already having a presence on US and Israeli networks prior to the current hostilities beginning means the threat group is in a potentially dangerous position to launch attacks,” the researchers noted.

It is unknown what tricks or exploits the APT used to gain initial access to these organizations’ networks.

Exposed VPS reveals Seedworm tooling

In related news, independent threat-intel research collective Ctrl-Alt-Intel recently claimed to have accessed infrastructure used by Seedworm / Muddy Water, which allowed them to harvest “C2 tooling, scripts, logs, victim data, and other operational artefacts from a VPS hosted in the Netherlands.”

Israeli healthcare and government organizations, EgyptAir, Jordan’s government, UAE businesses, US organizations, and Jewish/Israeli-linked NGOs.

The exposed infrastructure reveals details about a MuddyWater operation, from initial reconnaissance to data theft. The key takeaway is the scale of the operation rather than the complexity of individual tools. It involves numerous targeted organizations, several custom C2 frameworks, exploitation of various CVEs including new SQL injection vulnerabilities, password spraying, Ethereum-based C2 resolution, and multiple exfiltration methods including cloud storage and EC2 instances, the group stated.

“MuddyWater continues to demonstrate a willingness to rapidly adopt public exploit code, modify it for operational use, and deploy it at scale – all while developing custom tooling in parallel.”

Check Also

France

727,000 data exposes: French hospital fined €500,000

France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for …