The Iran-linked threat group MuddyWater (Seedworm) conducted a cyber-espionage campaign targeting at least nine organizations globally, including a major South Korean electronics manufacturer, government agencies, and an international airport. The February 2026 attack on the Korean firm lasted one week and involved DLL sideloading using legitimate binaries from Fortemedia and SentinelOne to load malicious DLLs containing the ChromElevator credential-stealing tool. Attackers used PowerShell controlled via Node.js loaders for reconnaissance, screenshot capture, credential theft (fake Windows prompts, registry hive theft, Kerberos ticket abuse), and SOCKS5 tunnel creation. Data was exfiltrated via the public file-sharing service sendit.sh to blend in with normal traffic. Symantec highlights the campaign's geographic expansion, operational maturity, and increasing reliance on legitimate tools to evade detection.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Fortemedia and SentinelOne abuseAttack on a Korean firmRelated Articles:
100 Impressions