A cyber-espionage group connected to Iran, commonly known as Seedworm (also referred to as MuddyWater, Temp Zagros, or Static Kitten), has reportedly infiltrated several U.S. organizations, raising concerns among cybersecurity experts. Investigators believe the group has been operating within American networks since early February 2026.
The increase in malicious cyber activity comes during a period of heightened geopolitical tension following joint military strikes by the United States and Israel against Iran on February 28, 2026. The attacks escalated regional conflict and appear to have triggered a surge in cyber operations by Iranian-linked actors targeting Western interests.

Expanding Targets Across Critical Sectors
Security researchers have identified multiple sectors that may have been affected. These include a U.S. financial institution, an airport, several nonprofit organizations in North America, and the Israeli branch of an American software supplier involved in the defense and aerospace industries.
By gaining access to these networks, attackers may position themselves to conduct future operations ranging from data theft and espionage to disruptive or destructive cyberattacks. Analysts warn that maintaining persistent access to high-value targets during an ongoing geopolitical conflict could enable rapid escalation if directed by state authorities.
New Malware and Attack Techniques
Researchers have also linked the campaign to new malicious tools, including backdoor malware that enables remote access to compromised systems. Once installed, these tools allow hackers to move through networks, steal sensitive data, and maintain long-term control over infected machines.
Such tactics are typical of advanced persistent threat (APT) groups, which focus on stealthy and prolonged infiltration rather than immediate disruption. These operations often involve spear-phishing emails, exploitation of system vulnerabilities, and the use of custom malware designed to evade detection.
Cyber Operations in Modern Conflict
Experts note that cyber activity is increasingly used as a strategic tool during geopolitical conflicts. Rather than relying solely on traditional military responses, nations may employ cyber campaigns to gather intelligence, disrupt adversaries, or create economic pressure.
The current wave of cyber activity highlights how digital infrastructure—including financial services, transportation networks, and defense suppliers—can become targets during periods of political and military tension.
Growing Concern for U.S. Infrastructure
The presence of Iranian-linked hackers within critical networks has prompted warnings from cybersecurity professionals. While there is no confirmation of large-scale disruption so far, the ability of attackers to maintain hidden access increases the risk of future incidents.
Organizations are therefore being urged to strengthen their cybersecurity defenses, monitor network activity closely, and quickly patch vulnerabilities to reduce the chances of compromise.
“In today’s world, conflicts are no longer fought only on battlefields but also through lines of code—where protecting critical infrastructure means safeguarding the stability and security of entire nations.”