FakeSet is a Python-based malware family associated with the Iranian state-linked espionage group MuddyWater, also tracked as Seedworm. It has been described both as a backdoor used to maintain covert access in compromised environments and as a downloader used to deliver CastleLoader, indicating a role in staged post-compromise operations. Observed activity places FakeSet in intrusions beginning in early 2026 against organizations in the United States, Israel, and Canada, including entities in banking, aviation, non-profit, and defense-adjacent sectors.
FakeSet has been used alongside other MuddyWater tooling, notably the Deno-based Dindoor implant and legacy families such as Stagecomp and Darkcomp. Its operational purpose appears to be long-term foothold establishment, support for follow-on payload delivery, and enabling broader espionage objectives. Campaign reporting links the broader intrusion set to credential harvesting, cloud administrative enumeration, Active Directory reconnaissance, Privileged Identity Management inventory, and data exfiltration attempts using legitimate cloud services and transfer tools. FakeSet itself was observed in victim environments where operators emphasized stealth, persistence, and blending malicious activity with trusted infrastructure.
Attribution to MuddyWater is supported by repeated reporting, overlaps with code-signing material previously associated with that actor’s malware ecosystem, and its co-occurrence with other MuddyWater implants in the same campaign cluster. The malware has been reported on networks of a U.S. airport, non-profit organizations, and other strategically relevant victims during a period of heightened regional tension. FakeSet reflects MuddyWater’s broader shift toward low-signature, behaviorally stealthy tradecraft that relies on legitimate services and modular tooling to preserve access and support intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign, publicly disclosed in early March 2026, leveraged two malware families Dindoor, a backdoor utilizing the Deno runtime, and Fakeset, a Python-based implant alongside legitimate tooling and cloud infrastructure to establish persistent access and enable data exfiltration.
The campaign, publicly disclosed in early March 2026, leveraged two malware families Dindoor, a backdoor utilizing the Deno runtime, and Fakeset, a Python-based implant alongside legitimate tooling and cloud infrastructure to establish persistent access and enable data exfiltration.
The group deployed two malware, a newly discovered backdoor called Dindoor and a Python-based tool called Fakeset, across multiple victim environments.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
“MuddyWater… had already planted backdoors inside a U.S. bank, airport, defense-adjacent software company, and NGOs… new implant named Dindoor… and… Python-based backdoor called Fakeset.”
The observed activity maps to several established ATT&CK techniques, including spearphishing for initial access, command and scripting interpreter abuse (expanded to include Deno), ingress tool transfer via cloud-hosted payloads, exfiltration over web services using Rclone, and application-layer command-and-control mechanisms.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A purported Python backdoor linked in public reporting to Seedworm, reportedly delivered from Backblaze servers and used alongside Rclone-based exfiltration to Wasabi cloud storage.
A Python backdoor observed on U.S. airport and nonprofit networks; certificate overlap and hosting artifacts linked it to Seedworm.
A Python-based implant/backdoor used by MuddyWater for pre-positioning access inside victim networks.
A Python-based malware/tool used in compromises, associated with payload delivery and data exfiltration activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.