Iran-linked APT targets US critical sectors with new backdoors

2026-03-06T14:51:46Z0f0f4085ee90bdc9ab4fe9070e4cf4120de1e58b7f6cbd878798cd087ba1f690
2026-02APTIranMOISMuddyWaterSeedwormSymantecUnited StatesVMware Carbon Blackbackdoorcritical infrastructurecyber operationsespionage

What happened

Iran-linked APT 'Seedworm' (aka MuddyWater), suspected to operate for Iran’s Ministry of Intelligence and Security (MOIS), has been active inside multiple US organizations since early February 2026. Symantec and VMware Carbon Black researchers attribute new backdoors to the group; victims include organizations in US critical sectors, raising concern the intrusions could precede wider cyber operations amid Middle East tensions. Activity represents an ongoing high-risk espionage/intrusion campaign with potential for escalation or disruptive follow-on operations.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
0f0f4085ee90bdc9ab4fe9070e4cf4120de1e58b7f6cbd878798cd087ba1f690
Enrichment time
2026-03-06T14:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.