Threats & Adversaries · DDoS

Iran-Linked Cyberattacks Surge After US‑Israel Operation Epic Fury

Iran-linked MuddyWater operators established persistent access in US and Israeli networks. Broadcom’s Symantec and Carbon Black found a Deno-based backdoor called Dindoor and a Python backdoor called Fakeset, both signed with certificates tied to MuddyWater, and saw an attempted rclone exfiltration to a Wasabi bucket. Confirmed targets include a US bank, a US airport, a Canadian non-profit, and the Israeli arm of a US defense/aerospace software supplier.

18 sources · Mar 24

Timeline

Sources

Part of the PlainSec briefing for 2026-03-07

Every edition of this story: Iran-Linked Cyberattacks Surge After US‑Israel Operation Epic Fury

More from today