Adversary Intelligence — 2026-05-16

Iranian MOIS-Linked Seedworm Group Deploys ChromElevator Malware via Hijacked Security Software in Global Campaign

BLUFWeaponizing SentinelOne's own binaries marks a tradecraft leap that erodes enterprise trust in endpoint protection, though a formal US or allied advisory naming this campaign remains unlikely before November 2026.

Iran Ministry of Intelligence-affiliated threat actor Seedworm, also tracked as MuddyWater, launched a global cyber espionage campaign in 2026 that hijacks legitimate security software through DLL sideloading to deploy a novel Node.js-based backdoor called ChromElevator, according to Symantec Threat Hunter researchers. The campaign exploits trust in security vendor software by sideloading malicious DLLs alongside legitimate SentinelOne components, allowing persistent access while evading endpoint detection. Targets include government agencies, telecommunications companies, and critical infrastructure across the Middle East, South Asia, and Western nations.

Analysis
Seedworm's DLL-sideloading of legitimate SentinelOne binaries weaponizes endpoint-protection software itself, a tradecraft shift that cuts against the trust model underlying enterprise security architectures, and one that outpaces MuddyWater's historical mid-tier reputation. Per Symantec alone, with no corroboration from other vendors or government CERTs, confidence in the full operational scope remains low. The global framing may instead reflect commercial incentive to characterize what is a targeted operation against SentinelOne-deployed organizations as a broad capability shift. A formal US or allied government advisory is unlikely by end of October 2026, leaving Symantec's attribution as the sole defensive resource and network defenders without coordinated IOCs or legal backing for infrastructure takedowns.
3 sources
  1. Seedworm 2026 Global Campaign Hijacks Security Software to Deploy ChromElevator - Security Online
  2. Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading - Cybersecurity News
  3. Seedworm APT Abuses Signed Binaries for DLL Sideloading - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE