Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations

2026-03-07T02:51:47Z1ea294c85bbb032989eea0c459d9fb100554620f87b71cce4d6203269d4d2b83
APTBadPawCISA KEVCVE-2023-43000CVE-2026-20122CVE-2026-20128Catalyst SD‑WANCiscoClickFixCorunaDindoorDust SpecterGoogle GTIGIran-linkedLeakBaseLumma StealerMeowMeowMuddyWaterPhobosRussian APTWindows TerminaliOS exploit kitransomwarezero-day

What happened

Security Affairs feed reports multiple high-impact cyber events: Iran-linked MuddyWater (SeedWorm) deployed a new Dindoor backdoor against U.S. organizations across sectors; Cisco warned of active in-the-wild exploitation of two recently patched Catalyst SD‑WAN vulnerabilities (CVE-2026-20128 and CVE-2026-20122) and urged patching; Microsoft disclosed a ClickFix campaign abusing Windows Terminal and social engineering to deliver Lumma Stealer; Iran-nexus Dust Specter targeted Iraqi officials with new malware families (SPLITDROP, TWINTASK, TWINTALK); CISA added multiple vulnerabilities (incl. i

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1ea294c85bbb032989eea0c459d9fb100554620f87b71cce4d6203269d4d2b83
Enrichment time
2026-03-07T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.