PULSE NAME
Iranian APT Seedworm Targets Global Organizations via Microsoft Teams
WHITE MuddyWater dylanroth7 2026-04-20 Modified: 2026-04-22
77
IOCs
HIGH VOLUME
In late February 2026, following escalating Middle East tensions and coordinated military actions, Iranian APT group Seedworm launched sophisticated social engineering attacks via Microsoft Teams. Attackers impersonated IT support personnel using deceptive Microsoft 365 tenant domains to convince victims to execute malicious MSI installers. The campaign deployed a custom backdoor called Dindoor, which leveraged legitimate Deno runtime to execute obfuscated payloads in-memory, minimizing detection. The operation included multiple components for persistence, command-and-control communications, and data exfiltration. Infrastructure overlapped with previously reported MuddyWater operations.
Indicators of Compromise (23 / 77 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2115e69f71d9f51a6c6c2effdaee2df2 2026-04-20
FileHash-MD5 29953b2e46aeaf0157d487c13c4a0643 2026-04-20
FileHash-MD5 3962bfa78c7acd8d85b3700e99ae8d24 2026-04-20
FileHash-MD5 41c19fc6c8a8687988f28fc487048bf3 2026-04-20
FileHash-MD5 439c0a0a46627bd166e08436f383ad56 2026-04-20
FileHash-MD5 4860758863fd040a8c809ce53cb7fb37 2026-04-20
FileHash-MD5 56a4b425aba37ef886bdfbd8343a1bd5 2026-04-20
FileHash-MD5 591aae15106147bdb5bc7b26049b943f 2026-04-20
FileHash-MD5 5c057af2f358fc10107d5ccdb39938ad 2026-04-20
FileHash-MD5 64e4b0ffd8bed9307eb50b541b1d8fdb 2026-04-20
FileHash-MD5 6d1d4e938ed1e46210375308ef3bcb08 2026-04-20
FileHash-MD5 7236f1a51da141e422d553e36ef6c9d0 2026-04-20
FileHash-MD5 76c59282e44a461105dc5739a6ba7c33 2026-04-20
FileHash-MD5 7a4119e116ecdefe0a1017110e250e61 2026-04-20
FileHash-MD5 7f3c8a7fe78d3d05b6022df3ea0c15fb 2026-04-20
FileHash-MD5 838c8fd4ae7e3c4972adc8800db44929 2026-04-20
FileHash-MD5 8d8aa0be8f82d22deab96f96d9af34b8 2026-04-20
FileHash-MD5 c0a52cd5dd35bf9d5d08c7eb12cfa422 2026-04-20
FileHash-MD5 c23fc7b74370d590223d962727e67907 2026-04-20
FileHash-MD5 ca37e31d651bbd5bbddef3ea716b8b4f 2026-04-20
FileHash-MD5 e2bcc41ddea5cf9d759380701d14f258 2026-04-20
FileHash-MD5 e6fafcb72f2f315692218182ba84e0ef 2026-04-20
FileHash-MD5 f8560b9a893eeb2130fc7159e9c1b851 2026-04-20