Fakeset
FakeSet is a Python-based backdoor/downloader associated with the Iranian threat actor MuddyWater, also known as Seedworm, which multiple sources in the content link to Iran’s Ministry of Intelligence and Security (MOIS). It was observed in intrusions beginning in February 2026 and was found on the networks of a U.S. airport, a U.S. non-profit, and in broader reporting tied to compromises affecting a U.S. bank, defense-adjacent software company, and NGOs in the U.S. and Canada. The malware is described both as a Python backdoor and as a downloader used in recent infection chains to deliver CastleLoader. Reporting states that FakeSet samples were signed with code-signing certificates issued to “Amy Cherne” and “Donald Gay,” with the Donald Gay certificate previously linked to other Seedworm-associated malware such as Stagecomp/Darkcomp. FakeSet was reportedly downloaded from Backblaze-hosted infrastructure, including gitempire.s3.us-east-005.backblazeb2.com and elvenforest.s3.us-east-005.backblazeb2.com. Across the cited reporting, FakeSet is characterized as part of MuddyWater’s persistence tooling, designed to remain hidden and preserve long-term footholds in victim environments. High-confidence victim sectors mentioned in the content include banking, aviation/transportation, nonprofits/NGOs, and defense supply chain or defense-adjacent organizations. Related activity in the same campaigns included attempted data exfiltration using Rclone to Wasabi cloud storage and deployment alongside the Deno-based backdoor Dindoor.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Fakeset [требует верификации] - Python-бэкдор. Предположительно подписан сертификатами «Amy Cherne» и «Donald Gay».
The group deployed two malware, a newly discovered backdoor called Dindoor and a Python-based tool called Fakeset, across multiple victim environments.
The group deployed two malware, a newly discovered backdoor called Dindoor and a Python-based tool called Fakeset, across multiple victim environments.
Techniques & procedures
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
2 techniques
Initial Access
Execution
2 techniques
Execution
Persistence
2 techniques
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Defense Impairment
1 technique
Defense Impairment
Collection
1 technique
Collection
Command and Control
2 techniques
Command and Control
Exfiltration
2 techniques
Exfiltration
IOCs tracked for this family
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A purported Python backdoor linked in public reporting to Seedworm, reportedly delivered from Backblaze servers and used alongside Rclone-based exfiltration to Wasabi cloud storage.
A Python backdoor observed on U.S. airport and nonprofit networks; certificate overlap and hosting artifacts linked it to Seedworm.
A Python-based implant/backdoor used by MuddyWater for pre-positioning access inside victim networks.
A Python-based malware/tool used in compromises, associated with payload delivery and data exfiltration activity.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.