← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Iranian APT Seedworm Targets Global Organizations via Microsoft Teams
In late February 2026, following escalating Middle East tensions and coordinated military actions, Iranian APT group Seedworm launched sophisticated social engineering attacks via Microsoft Teams. Attackers impersonated IT support personnel using deceptive Microsoft 365 tenant domains to convince victims to execute malicious MSI installers. The campaign deployed a custom backdoor called Dindoor, which leveraged legitimate Deno runtime to execute obfuscated payloads in-memory, minimizing detection. The operation included multiple components for persistence, command-and-control communications, and data exfiltration. Infrastructure overlapped with previously reported MuddyWater operations.
MITRE ATT&CK & Malware Families
Indicators of Compromise (23 / 77 total)