---
title: "Iranian hackers targeted major South Korean electronics maker"
url: https://daily.dev/posts/iranian-hackers-targeted-major-south-korean-electronics-maker-73rq7fupn
source_url: https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-major-south-korean-electronics-maker
type: article
source: "BleepingComputer"
published: 2026-05-13T22:04:27.951Z
updated: 2026-05-13T22:44:51.208Z
tags: ["security", "malware"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Iranian hackers targeted major South Korean electronics maker

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

The Iran-linked threat group MuddyWater (Seedworm) conducted a cyber-espionage campaign targeting at least nine organizations globally, including a major South Korean electronics manufacturer, government agencies, and an international airport. The February 2026 attack on the Korean firm lasted one week and involved DLL sideloading using legitimate binaries from Fortemedia and SentinelOne to load malicious DLLs containing the ChromElevator credential-stealing tool. Attackers used PowerShell controlled via Node.js loaders for reconnaissance, screenshot capture, credential theft (fake Windows prompts, registry hive theft, Kerberos ticket abuse), and SOCKS5 tunnel creation. Data was exfiltrated via the public file-sharing service sendit.sh to blend in with normal traffic. Symantec highlights the campaign's geographic expansion, operational maturity, and increasing reliance on legitimate tools to evade detection.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-major-south-korean-electronics-maker>

## Similar posts on daily.dev

- [Iran intelligence backdoored US bank, airport networks](https://daily.dev/posts/iran-intelligence-backdoored-us-bank-airport-networks-cxmgee8y5) · The Register · 1 upvotes · 0 comments
- [Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks](https://daily.dev/posts/iran-linked-hackers-hits-israeli-sectors-with-new-muddyviper-backdoor-in-targeted-attacks-2yw0reqpt) · The Hacker News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/iranian-hackers-targeted-major-south-korean-electronics-maker-73rq7fupn)
