Fakeset is a Python-based backdoor/downloader associated with the Iran-aligned threat actor MuddyWater, also tracked as Seedworm and linked in the reporting to Iran’s Ministry of Intelligence and Security (MOIS). Public reporting in early 2026 places Fakeset in a coordinated intrusion campaign targeting organizations in the United States, Israel, and Canada, including a U.S. airport, a U.S. bank, nonprofit organizations, and the Israeli subsidiary of a U.S. software company supporting defense and aerospace customers. The malware was used alongside the Deno-based backdoor Dindoor, as well as legacy MuddyWater tooling including Stagecomp and Darkcomp, to establish persistent access and support intelligence collection and data exfiltration. Multiple sources in the content describe Fakeset as a Python backdoor; some also describe it as a downloader used to deliver CastleLoader. Reported operator activity around these intrusions included credential harvesting, cloud administrator enumeration, Active Directory reconnaissance, Privileged Identity Management inventory, Intune estate mapping, and attempted exfiltration using Rclone to Wasabi, with supporting delivery or staging infrastructure hosted on Backblaze B2. Fakeset was observed on U.S. airport and nonprofit networks and was reportedly downloaded from Backblaze-hosted servers. Samples were signed with certificates issued to “Amy Cherne” and “Donald Gay,” and the content states these certificates were also associated with MuddyWater-linked Stagecomp and Darkcomp, strengthening attribution. High-confidence indicators directly mentioned in the content include the certificate subjects Amy Cherne and Donald Gay, Backblaze-hosted delivery infrastructure including gitempire.s3.us-east-005.backblazeb2.com and elvenforest.s3.us-east-005.backblazeb2.com, and repeated association with MuddyWater/Seedworm operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign, publicly disclosed in early March 2026, leveraged two malware families Dindoor, a backdoor utilizing the Deno runtime, and Fakeset, a Python-based implant alongside legitimate tooling and cloud infrastructure to establish persistent access and enable data exfiltration.
The campaign, publicly disclosed in early March 2026, leveraged two malware families Dindoor, a backdoor utilizing the Deno runtime, and Fakeset, a Python-based implant alongside legitimate tooling and cloud infrastructure to establish persistent access and enable data exfiltration.
The group deployed two malware, a newly discovered backdoor called Dindoor and a Python-based tool called Fakeset, across multiple victim environments.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The observed activity maps to several established ATT&CK techniques, including spearphishing for initial access, command and scripting interpreter abuse (expanded to include Deno), ingress tool transfer via cloud-hosted payloads, exfiltration over web services using Rclone, and application-layer command-and-control mechanisms.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A purported Python backdoor linked in public reporting to Seedworm, reportedly delivered from Backblaze servers and used alongside Rclone-based exfiltration to Wasabi cloud storage.
A Python backdoor observed on U.S. airport and nonprofit networks; certificate overlap and hosting artifacts linked it to Seedworm.
A Python-based implant/backdoor used by MuddyWater for pre-positioning access inside victim networks.
A Python-based malware/tool used in compromises, associated with payload delivery and data exfiltration activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.