Iran-linked APT targets US critical sectors with new backdoors
2026-03-06T14:51:46Z•0f0f4085ee90bdc9ab4fe9070e4cf4120de1e58b7f6cbd878798cd087ba1f690
2026-02APTIranMOISMuddyWaterSeedwormSymantecUnited StatesVMware Carbon Blackbackdoorcritical infrastructurecyber operationsespionage
What happened
Iran-linked APT 'Seedworm' (aka MuddyWater), suspected to operate for Iran’s Ministry of Intelligence and Security (MOIS), has been active inside multiple US organizations since early February 2026. Symantec and VMware Carbon Black researchers attribute new backdoors to the group; victims include organizations in US critical sectors, raising concern the intrusions could precede wider cyber operations amid Middle East tensions. Activity represents an ongoing high-risk espionage/intrusion campaign with potential for escalation or disruptive follow-on operations.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 0f0f4085ee90bdc9ab4fe9070e4cf4120de1e58b7f6cbd878798cd087ba1f690
- Enrichment time
- 2026-03-06T14:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.