Iran-Linked Cyberattacks Surge After US‑Israel Operation Epic Fury
Iran-linked MuddyWater operators established persistent access in US and Israeli networks. Broadcom’s Symantec and Carbon Black found a Deno-based backdoor called Dindoor and a Python backdoor called Fakeset, both signed with certificates tied to MuddyWater, and saw an attempted rclone exfiltration to a Wasabi bucket. Confirmed targets include a US bank, a US airport, a Canadian non-profit, and the Israeli arm of a US defense/aerospace software supplier.
Iran-linked ransomware gang targeted US healthcare org amid military conflict
The incident responders noted that there was no evidence that data was exfiltrated during the intrusion — an unusual development considering U.S. intelligence agencies previously said Pay2Key attacks were largely conducted for information theft.