Iran-nexus cyber activity intensified alongside regional military escalation, with multiple reporting streams describing both opportunistic and targeted operations. Check Point Research observed a coordinated campaign to compromise internet-connected IP cameras across Israel, the UAE, Qatar, Bahrain, Kuwait, Lebanon, and Cyprus, with spikes in exploitation attempts aligning to geopolitical events; activity was traced to infrastructure linked to Iran-nexus actors using commercial VPN exit nodes (e.g., Mullvad, ProtonVPN, Surfshark, NordVPN) and VPS infrastructure to mask origin, and the most targeted vendors were Hikvision and Dahua. Separately, Symantec reported Seedworm (MuddyWater/Temp Zagros/Static Kitten) activity on multiple U.S. and Canadian organizations beginning in February 2026, including a U.S. bank, airport, non-profit, and the Israeli operations of a U.S. software supplier to defense/aerospace; Symantec identified a previously unknown backdoor dubbed Dindoor (leveraging the Deno runtime) and a Python backdoor Fakeset, with malware signed using certificates issued to “Amy Cherne” (and in some cases “Donald Gay”), and noted attempted data exfiltration using Rclone to a Wasabi cloud storage bucket.
Additional coverage indicates broader pro-Iranian cyber activity but is less specific to the above intrusions. ASEC’s weekly “Ransom & Dark Web Issues” roundup flags pro-Iranian/pro-Islamist hacktivist attacks against Middle Eastern and pro-Western targets, but provides limited technical detail in the excerpt. A podcast episode describing “Iran’s 12 days of cyber war” and global OT targeting (including Unitronics PLCs) is largely commentary and retrospective framing rather than a discrete, verifiable incident report, and two other items in the set (a Russia-linked APT28 phishing/malware campaign in Ukraine and a China-nexus UAT-9244 telecom intrusion set in South America) describe unrelated threat activity outside the Iran-focused escalation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Help Net Security reported that the Ctrl-Alt-Intel collective claimed to have accessed a Seedworm/MuddyWater VPS in the Netherlands and recovered command-and-control tooling and victim data. The claim also described broader targeting across Israel, the Middle East, and the U.S., along with tradecraft such as password spraying, CVE exploitation, Ethereum-based C2 resolution, and multiple exfiltration channels.
Reporting on Check Point's findings revealed that Iranian-aligned actors were exploiting five known vulnerabilities and exposed access paths in Hikvision and Dahua devices across the Middle East. The disclosure highlighted the risk that compromised cameras could provide real-time visual intelligence for military targeting and battle damage assessment.
Symantec reported that Seedworm/MuddyWater had targeted multiple U.S. and Canadian organizations since February 2026 and identified a new Deno-based backdoor named Dindoor, along with a Python backdoor called Fakeset. The report also described attempted exfiltration using Rclone to a Wasabi bucket and attribution evidence from reused code-signing certificates.
ASEC said pro-Iranian and pro-Islamist hacktivist groups carried out cyber attacks against Middle Eastern and pro-Western targets. The roundup framed this as part of the threat activity observed in early March 2026.
ASEC reported that the Morpheus ransomware operation attacked a plating company in South Korea. The incident was included in ASEC's week 1 March 2026 ransomware and dark web roundup.
ASEC reported that the Ailock ransomware group became active again and republished data from previous victims. The roundup did not provide a more specific date than its week-one-of-March reporting window.
Researchers said Seedworm/MuddyWater operations increased after the February 28 strikes, with existing footholds in victim networks potentially positioned for espionage, disruption, or future destructive actions.
Multiple reports said Iranian cyber operations intensified after U.S. and Israeli military strikes on Iran. The cited date for the strikes was February 28, 2026, and researchers assessed some intrusions had been pre-positioned before the conflict escalation.
Check Point researchers observed an Iran-nexus campaign targeting internet-exposed Hikvision and Dahua cameras across multiple Middle East countries starting in late February 2026. The activity was assessed as supporting intelligence collection for possible kinetic operations.
Researchers reported that Seedworm/MuddyWater activity inside multiple organizations began in early February 2026, affecting a U.S. bank, a U.S. airport, nonprofits in the U.S. and Canada, and the Israeli operations of a U.S. software supplier tied to defense and aerospace.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcefieldeffect.com
Open sourcesecurityaffairs.com
Open sourcescmagazine.com
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourcesecurity.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.