Adversary Intelligence — 2026-05-16
Iranian MOIS-Linked Seedworm Group Deploys ChromElevator Malware via Hijacked Security Software in Global Campaign
BLUFWeaponizing SentinelOne's own binaries marks a tradecraft leap that erodes enterprise trust in endpoint protection, though a formal US or allied advisory naming this campaign remains unlikely before November 2026.
Iran Ministry of Intelligence-affiliated threat actor
Analysis
Seedworm's DLL-sideloading of legitimate SentinelOne binaries weaponizes endpoint-protection software itself, a tradecraft shift that cuts against the trust model underlying enterprise security architectures, and one that outpaces MuddyWater's historical mid-tier reputation. Per Symantec alone, with no corroboration from other vendors or government CERTs, confidence in the full operational scope remains low. The global framing may instead reflect commercial incentive to characterize what is a targeted operation against SentinelOne-deployed organizations as a broad capability shift. A formal US or allied government advisory isunlikely by end of October 2026, leaving Symantec's attribution as the sole defensive resource and network defenders without coordinated IOCs or legal backing for infrastructure takedowns.
Seedworm's DLL-sideloading of legitimate SentinelOne binaries weaponizes endpoint-protection software itself, a tradecraft shift that cuts against the trust model underlying enterprise security architectures, and one that outpaces MuddyWater's historical mid-tier reputation. Per Symantec alone, with no corroboration from other vendors or government CERTs, confidence in the full operational scope remains low. The global framing may instead reflect commercial incentive to characterize what is a targeted operation against SentinelOne-deployed organizations as a broad capability shift. A formal US or allied government advisory is