PULSE NAME
Iranian APT on Networks of U.S. Bank, Airport, Software Company
WHITE MuddyWater AlienVault 2026-03-05 Modified: 2026-03-06
54
IOCs
HIGH VOLUME
Iranian APT group Seedworm has been active on networks of multiple U.S. companies since February 2026, targeting a bank, airport, software company, and NGOs. The group deployed new backdoors named Dindoor and Fakeset, signed with certificates previously linked to Seedworm. The activity occurs amid escalating tensions between the U.S., Israel, and Iran. Seedworm, known for espionage and information gathering, has broadened its scope to target various sectors globally. The article discusses recent Iranian cyber activities, potential future threats, and provides recommendations for defenders to prepare against DDoS, credential attacks, leaks, critical infrastructure attacks, and destructive operations.
Indicators of Compromise (11 / 54 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0ba2306ec15f7124fafc7615e81f34c7986ba9a5 2026-03-05
FileHash-SHA1 2b781b3a352db44db67ad56e8477e6a1016b2597 2026-03-05
FileHash-SHA1 3ab3fee4daac90bb7bee470b5b2de8ee0d6bec8b 2026-03-05
FileHash-SHA1 429efcf0370b53cc3c455b634dc066b1d08b568d 2026-03-05
FileHash-SHA1 7a8963d123918ca86727649492cd1ff4e020cb72 2026-03-05
FileHash-SHA1 9c5cc25e80df75f91873bf31a6269e7bdab7c6d2 2026-03-05
FileHash-SHA1 a42b4914b0c8dc47a3a5f8114d0fcbef02d84e0a 2026-03-05
FileHash-SHA1 be3c8f93e9d7f42ec1133ab36f555b104b23fe1b 2026-03-05
FileHash-SHA1 c16099c29ccdb34764e4d15b1dab2d141d159950 2026-03-05
FileHash-SHA1 cecf87d582b4df4323eaef04c9a648d43325043a 2026-03-05
FileHash-SHA1 fa49d1fd5a938b3de0840759db62867e6382cea1 2026-03-05