Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
MuddyWater's Operation Olalampo Targets MENA Region with New Malware
MuddyWater, an advanced persistent threat (APT) group, has launched 'Operation Olalampo,' targeting organizations and individuals in the MENA region amid ongoing geopolitical tensions. The operation involves the…
3 articles · Updated April 11, 2026 -
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Microsoft Word Vulnerability CVE-2026-21514 Exposes Millions to Malware Attacks
CVE-2026-21514 is a security feature bypass vulnerability in Microsoft Word, disclosed on February 10, 2026. This flaw allows attackers to exploit nearly 14 million assets across seven Tier 1 countries, primarily in the…
5 articles · Updated March 18, 2026 -
China-Linked Hackers Deploy PlugX Malware in Qatar via Fake War News
China-linked hackers targeted Qatar by using fake war news to distribute PlugX backdoor malware. This attack aims to infiltrate and spy on critical sectors, including military and energy. The operation highlights the…
4 articles · Updated March 10, 2026 -
Iran-Linked Threat Actors Deploy Dindoor Backdoor via Deno Runtime
Iran-linked threat actors associated with MuddyWater are exploiting a Windows backdoor named Dindoor. This malware utilizes the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads, making…
2 articles · Updated August 26, 2026 -
MuddyWater-Style Hackers Target 12,000+ Systems in Middle East Cyber Campaign
A threat group resembling MuddyWater has executed a reconnaissance and intrusion operation targeting over 12,000 internet-facing systems in the Middle East. The attack focused on critical sectors, including aviation,…
2 articles · Updated April 15, 2026 -
Boggy Serpens Escalates Cyberespionage Against Diplomats and Infrastructure
The Iranian nation-state group Boggy Serpens, also known as MuddyWater, has intensified its cyberespionage activities, targeting diplomatic missions, energy companies, maritime operators, and financial institutions.…
2 articles · Updated March 18, 2026 -
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
33 articles · Updated May 19, 2026
Recent Intelligence Reports
- 3SBZ5Ky — trmlink.info · August 28, 2026
- Iran — Gbhackers · August 26, 2026
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- 826591 — www.cybersecuritydive.com · August 5, 2026
- Chaos in Teams vishing — Sophos · July 28, 2026
- 001 — attack.mitre.org · July 23, 2026
- Iran's APTs and the US Enterprise in 2026 — Kelacyber · July 22, 2026
- APT42: Iran's Human-Centric Espionage in 2026 — Kelacyber · July 22, 2026