Wednesday , October 7 2026
Seedworm

Seedworm hackers found inside US bank, airline, tech networks

An Iran-related hacking group (Seedworm) has infiltrated multiple US organizations since early February, heightening fears of potential larger cyber operations linked to rising geopolitical tensions in the Middle East.

New backdoors used by Seedworm

Contract and server dispute brought down Bangladesh’s digital payment

Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
Contract and server dispute brought down Bangladesh’s digital payment

Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Researchers from Symantec and Carbon Black have connected the activity to Seedworm (also known as MuddyWater), an Iranian group linked to the Ministry of Intelligence and Security, known for targeting government and critical infrastructure.

According to researchers, suspicious activity linked to Seedworm has been identified on the networks of:

A US bank
A US airport
Non-profit organizations, and
The Israeli operations of a US software company that supplies the defense and aerospace industries.

The activity started in early February 2026 and is still ongoing, with the group using new malware.

  • The Dindoor backdoor, named thus due to its use of Deno, a runtime environment for JavaScript and TypeScript, for executing commands on infected machines
  • A Python-based backdoor called Fakeset.

According to the researchers, Dindoor was digitally signed with a certificate issued to an individual named “Amy Cherne”. Fakeset was also signed, using using certificates attributed to both “Amy Cherne” and “Donald Gay,” the latter of which has previously been associated with the Stagecomp and Darkcomp malware used by the Seedworm APT.

The attackers appear to be spying; they aim to steal data from the software company and upload it to a Wasabi cloud storage bucket using the Rclone tool.

“While it’s not known if the operations of Seedworm are disrupted by the current conflict, already having a presence on US and Israeli networks prior to the current hostilities beginning means the threat group is in a potentially dangerous position to launch attacks,” the researchers noted.

It is unknown what tricks or exploits the APT used to gain initial access to these organizations’ networks.

Exposed VPS reveals Seedworm tooling

In related news, independent threat-intel research collective Ctrl-Alt-Intel recently claimed to have accessed infrastructure used by Seedworm / Muddy Water, which allowed them to harvest “C2 tooling, scripts, logs, victim data, and other operational artefacts from a VPS hosted in the Netherlands.”

Israeli healthcare and government organizations, EgyptAir, Jordan’s government, UAE businesses, US organizations, and Jewish/Israeli-linked NGOs.

The exposed infrastructure reveals details about a MuddyWater operation, from initial reconnaissance to data theft. The key takeaway is the scale of the operation rather than the complexity of individual tools. It involves numerous targeted organizations, several custom C2 frameworks, exploitation of various CVEs including new SQL injection vulnerabilities, password spraying, Ethereum-based C2 resolution, and multiple exfiltration methods including cloud storage and EC2 instances, the group stated.

“MuddyWater continues to demonstrate a willingness to rapidly adopt public exploit code, modify it for operational use, and deploy it at scale – all while developing custom tooling in parallel.”

Check Also

JadePuffer

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal …