Adversary Intelligence — 2026-05-27

Iran-Linked MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting Nine Countries

BLUFMuddyWater's weaponization of signed security-vendor binaries likely yields at least one additional publicly attributed campaign by year-end 2026, exposing endpoint tooling itself as the soft underbelly of defender stacks.

Symantec's Threat Hunter Team reported nine victim organizations across nine countries on four continents in the first quarter of 2026, including a major South Korean electronics manufacturer and an international airport in the Middle East 12. Attackers sideloaded malicious DLLs through two legitimately signed binaries, Fortemedia's fmapp.exe and SentinelOne's sentinelmemoryscanner.exe, with both files embedding ChromElevator to extract passwords, cookies, and payment data from Chromium-based browsers 12. A Node.js-based implant chain drove PowerShell scripts for reconnaissance, screenshot capture, SAM hive theft, privilege escalation, and SOCKS5 reverse-proxy tunneling, with stolen data staged on the public file-transfer service sendit[.]sh 12. In the South Korean intrusion, Broadcom's researchers reported the attackers spent a week inside the network in February 2026, repeatedly re-executing the signed binaries to maintain access; the initial access vector is unknown 1.

Analysis
The shift to Node.js implants and public exfiltration services displaces detection from network signatures to endpoint behavioral analytics, a transition most target sectors have not completed. Reuse of legitimately signed security-product binaries, including a SentinelOne component, reflects explicit intent to subvert endpoint tooling itself. MuddyWater will likely widen that detection gap through at least one additional publicly attributed campaign by year-end 2026. A contractor reusing known tooling remains a credible competing explanation, since attribution rests on TTP overlap without direct infrastructure fingerprinting. Low confidence reflects that single vendor report without corroborating signals intelligence. Security operations teams at critical infrastructure operators should accelerate behavioral endpoint detection for signed-binary DLL load abuse rather than waiting for signature updates that arrive after attribution.
3 sources
  1. MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries - The Hacker News
  2. Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading - CybersecurityNews
  3. Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign - Symantec Threat Hunter Team (Broadcom / security.com)

View in full brief →

UNCLASSIFIED // OPEN SOURCE