Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Nation-State

Iranian APT Hacked US Airport, Bank, Software Company

The attacks, observed since February, show that Iranian hackers already have a presence in the networks of US organizations.

Iranian hacker

The Iranian APT MuddyWater has hacked into the networks of several organizations in the US, including an aerospace and defense contractor, Broadcom’s Symantec and Carbon Black threat hunting team reports.

The threat actor has been present in the environments of an airport, a bank, a non-governmental organization operating in the US and Canada, and a software company with a presence in Israel.

According to the Broadcom experts, the APT’s activity has continued “in recent days following US and Israeli military strikes on Iran that have sparked conflict in the region”.

The compromised software firm, an aerospace and defense contractor, also has a presence in Israel, making it a target of interest for MuddyWater hackers.

As part of the campaign, the APT deployed a new backdoor dubbed Dindoor on the networks of the software supplier’s Israeli branch, the US bank, and the Canadian NGO.

The backdoor is signed with a certificate issued for ‘Amy Cherne’. The APT also attempted to exfiltrate data from the software company’s Israeli branch.

Advertisement. Scroll to continue reading.

Broadcom’s cybersecurity team also discovered a Python backdoor dubbed Fakeset on the networks of a US airport and a non-profit organization, also signed with an Amy Cherne certificate and with a certificate issued for ‘Donald Gay’, which was used in previous MuddyWater attacks as well.

The observed activity has been disrupted, but other organizations might still be vulnerable to compromise, the Symantec and Carbon Black team says.

“While it’s not known if the operations of Seedworm are disrupted by the current conflict, already having a presence on U.S. and Israeli networks prior to the current hostilities beginning means the threat group is in a potentially dangerous position to launch attacks,” the experts note.

Active since at least 2017 and also known as Mango Sandstorm, Mercury, Seedworm, and Static Kitten, MuddyWater has been officially linked by the US to the Iranian Ministry of Intelligence and Security (MOIS).

The threat actor is known for targeting entities in the Middle East as part of espionage operations, and was seen last year deploying updated Android spyware during the Israel-Iran conflict.

Last year, Amazon detailed the APT’s involvement in cyber-enabled kinetic targeting, hacking into live CCTV streams from Jerusalem in support of a missile attack.

Related: Iranian Strikes on Amazon Data Centers Highlight Industry’s Vulnerability to Physical Disasters

Related: Iran Cyber Front: Hacktivist Activity Rises, but State-Sponsored Attacks Stay Low

Related: US-Israel and Iran Trade Cyberattacks: Pro-West Hacks Cause Disruption as Tehran Retaliates

Related: US Posts $10 Million Bounty for Iranian Hackers

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Cyera has appointed Naveen Palavalli as Chief Marketing Officer.

Connie Devine has been promoted to Chief Information Security Officer at Phillips 66.

Jeff Lunglhofer becomes Chief Security Officer at Coinbase, replacing Philip Martin.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.