← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Iranian APT on Networks of U.S. Bank, Airport, Software Company
Iranian APT group Seedworm has been active on networks of multiple U.S. companies since February 2026, targeting a bank, airport, software company, and NGOs. The group deployed new backdoors named Dindoor and Fakeset, signed with certificates previously linked to Seedworm. The activity occurs amid escalating tensions between the U.S., Israel, and Iran. Seedworm, known for espionage and information gathering, has broadened its scope to target various sectors globally. The article discusses recent Iranian cyber activities, potential future threats, and provides recommendations for defenders to prepare against DDoS, credential attacks, leaks, critical infrastructure attacks, and destructive operations.
MITRE ATT&CK & Malware Families
Indicators of Compromise (11 / 54 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 29953b2e46aeaf0157d487c13c4a0643 | — | 2026-03-05 | |
| FileHash-MD5 | 439c0a0a46627bd166e08436f383ad56 | — | 2026-03-05 | |
| FileHash-MD5 | 4860758863fd040a8c809ce53cb7fb37 | — | 2026-03-05 | |
| FileHash-MD5 | 56a4b425aba37ef886bdfbd8343a1bd5 | — | 2026-03-05 | |
| FileHash-MD5 | 591aae15106147bdb5bc7b26049b943f | — | 2026-03-05 | |
| FileHash-MD5 | 76c59282e44a461105dc5739a6ba7c33 | — | 2026-03-05 | |
| FileHash-MD5 | 7a4119e116ecdefe0a1017110e250e61 | — | 2026-03-05 | |
| FileHash-MD5 | 7f3c8a7fe78d3d05b6022df3ea0c15fb | — | 2026-03-05 | |
| FileHash-MD5 | 838c8fd4ae7e3c4972adc8800db44929 | — | 2026-03-05 | |
| FileHash-MD5 | e2bcc41ddea5cf9d759380701d14f258 | — | 2026-03-05 | |
| FileHash-MD5 | e6fafcb72f2f315692218182ba84e0ef | — | 2026-03-05 |