TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Iran's MuddyWater Hackers Hit US Firms with New 'Dindoor' Backdoor

2026-03-06 · Read original ↗

ATT&CK techniques detected

3 predictions
T1588.003Code Signing Certificates
60%
“iran ' s muddywater hackers hit us firms with new ' dindoor ' backdoor several us companies have been targeted by iranian hacking group muddywater in a new campaign that started in early february and has continued after the us and israeli military strikes on iran. the campaign wa…”
T1048Exfiltration Over Alternative Protocol
54%
“leverages deno, the secure runtime for javascript and typescript, to execute. the researchers also observed an attempt to exfiltrate data from the software company using rclone, a command - line program to manage files on cloud storage, to a wasabi cloud storage bucket. it is not…”
T1105Ingress Tool Transfer
33%
“leverages deno, the secure runtime for javascript and typescript, to execute. the researchers also observed an attempt to exfiltrate data from the software company using rclone, a command - line program to manage files on cloud storage, to a wasabi cloud storage bucket. it is not…”

Summary

A bank, an airport, a non-profit and the Israeli branch of a US software company were among the targets of this new MuddyWater campaign