Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
2026-03-07T02:51:47Z•1ea294c85bbb032989eea0c459d9fb100554620f87b71cce4d6203269d4d2b83
APTBadPawCISA KEVCVE-2023-43000CVE-2026-20122CVE-2026-20128Catalyst SD‑WANCiscoClickFixCorunaDindoorDust SpecterGoogle GTIGIran-linkedLeakBaseLumma StealerMeowMeowMuddyWaterPhobosRussian APTWindows TerminaliOS exploit kitransomwarezero-day
What happened
Security Affairs feed reports multiple high-impact cyber events: Iran-linked MuddyWater (SeedWorm) deployed a new Dindoor backdoor against U.S. organizations across sectors; Cisco warned of active in-the-wild exploitation of two recently patched Catalyst SD‑WAN vulnerabilities (CVE-2026-20128 and CVE-2026-20122) and urged patching; Microsoft disclosed a ClickFix campaign abusing Windows Terminal and social engineering to deliver Lumma Stealer; Iran-nexus Dust Specter targeted Iraqi officials with new malware families (SPLITDROP, TWINTASK, TWINTALK); CISA added multiple vulnerabilities (incl. i
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1ea294c85bbb032989eea0c459d9fb100554620f87b71cce4d6203269d4d2b83
- Enrichment time
- 2026-03-07T02:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.