PULSE NAME
Iranian APT on Networks of U.S. Bank, Airport, Software Company
WHITE MuddyWater AlienVault 2026-03-05 Modified: 2026-03-06
54
IOCs
HIGH VOLUME
Iranian APT group Seedworm has been active on networks of multiple U.S. companies since February 2026, targeting a bank, airport, software company, and NGOs. The group deployed new backdoors named Dindoor and Fakeset, signed with certificates previously linked to Seedworm. The activity occurs amid escalating tensions between the U.S., Israel, and Iran. Seedworm, known for espionage and information gathering, has broadened its scope to target various sectors globally. The article discusses recent Iranian cyber activities, potential future threats, and provides recommendations for defenders to prepare against DDoS, credential attacks, leaks, critical infrastructure attacks, and destructive operations.
Indicators of Compromise (11 / 54 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 29953b2e46aeaf0157d487c13c4a0643 2026-03-05
FileHash-MD5 439c0a0a46627bd166e08436f383ad56 2026-03-05
FileHash-MD5 4860758863fd040a8c809ce53cb7fb37 2026-03-05
FileHash-MD5 56a4b425aba37ef886bdfbd8343a1bd5 2026-03-05
FileHash-MD5 591aae15106147bdb5bc7b26049b943f 2026-03-05
FileHash-MD5 76c59282e44a461105dc5739a6ba7c33 2026-03-05
FileHash-MD5 7a4119e116ecdefe0a1017110e250e61 2026-03-05
FileHash-MD5 7f3c8a7fe78d3d05b6022df3ea0c15fb 2026-03-05
FileHash-MD5 838c8fd4ae7e3c4972adc8800db44929 2026-03-05
FileHash-MD5 e2bcc41ddea5cf9d759380701d14f258 2026-03-05
FileHash-MD5 e6fafcb72f2f315692218182ba84e0ef 2026-03-05