MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

First seen 22 Jul 2026, 18:55 UTC Kelacyberattack.mitre.orgwww.trendmicro.commei.educloud.google.com 94% similarity 77.9

Article Content

Browse articles
ThreatCluster

In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with heightened geopolitical tensions in the Middle East. MuddyWater utilized a previously undocumented backdoor named Dindoor for these operations, exfiltrating data via Rclone to Wasabi cloud storage. The group has evolved from regional espionage to a more aggressive global strategy, affecting critical infrastructure. The attacks are characterized by the use of legitimate tools to blend with normal enterprise activity, posing significant risks to U.S. enterprises. Current assessments indicate that the group is actively exploiting vulnerabilities, including CVE-2024-30088, which was added to CISA's KEV list for active exploitation. Security professionals are urged to bolster defenses against these sophisticated threats.

Key Points: • MuddyWater targeted U.S. banking and infrastructure in early 2026 amid geopolitical tensions. • The group deployed a new backdoor named Dindoor for data exfiltration using Rclone. • CVE-2024-30088 is actively exploited in these operations, heightening the urgency for defenses.

ThreatCluster AI

Timeline

2024-06-11
CVE-2024-30088 published
A critical vulnerability was published, later exploited by various threat actors including MuddyWater.
Known CVE Dates
2024-10-15
CVE-2024-30088 added to CISA KEV
CISA added CVE-2024-30088 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Known CVE Dates
2026-02-01
MuddyWater begins targeting U.S. entities
The group launched attacks against U.S. banking and a major airport, coinciding with geopolitical tensions.
Kelacyber
2026-03-01
Intensified cyber operations reported
MuddyWater's cyber operations escalated, utilizing the Dindoor backdoor for data exfiltration.
Kelacyber

Community

Browse all →