Adversary Intelligence — 2026-05-14

Seedworm APT Breached Major South Korean Electronics Maker Using DLL Sideloading of Signed Binaries

Symantec and Broadcom reported on May 13 that Iran-linked Seedworm spent roughly one week inside a major South Korean electronics manufacturer in February 2026, part of a first-quarter campaign that struck at least nine organizations across four continents. Other targets included government agencies and an international airport in the Middle East, industrial manufacturers in Southeast Asia, and a financial-services firm in Latin America. The attackers used DLL sideloading through legitimately signed Fortemedia and SentinelOne binaries, with Node.js scripts orchestrating each stage; initial access into the Korean network was not determined. Credential operations included SAM hive extraction and Kerberos TGT harvesting via GSS-API delegation abuse, with collected data exfiltrated through sendit[.]sh, a public file-transfer service.

Analysis
Corroborated by Symantec and Broadcom, Seedworm's Q1 2026 campaign marks a geographic expansion for a Middle East-focused MOIS platform, with the South Korean electronics intrusion likely reflecting Tehran's interest in semiconductor IP. Operators built redundancy into credential operations: SAM hive extraction, Kerberos TGT harvesting via GSS-API delegation abuse, and credential dialog spoofing, anticipating that endpoint controls would block some techniques. Sideloading through a signed SentinelOne binary exploits defender trust in security-product processes; the shift from Deno to Node.js signals runtime rotation to frustrate behavioral detection. Exfiltration through sendit[.]sh follows documented Iranian tradecraft blending stolen data into consumer file-sharing traffic. The campaign's geographic breadth may instead reflect loosely directed contractor activity under nominal MOIS oversight, implying opportunistic rather than strategic targeting.
4 sources
  1. Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign - Symantec/SECURITY.COM
  2. Iranian hackers targeted major South Korean electronics maker - BleepingComputer
  3. Symantec uncovers Iran-linked Seedworm espionage campaign targeting airport, government, manufacturing sectors - Industrial Cyber
  4. Iran-Linked Hackers Breached Major Korean Electronics Maker in Global Espionage Campaign - Broadcom

View in full brief →

UNCLASSIFIED // OPEN SOURCE