Seedworm APT Breached Major South Korean Electronics Maker Using DLL Sideloading of Signed Binaries
Symantec and Broadcom reported on May 13 that Iran-linked
Corroborated by Symantec and Broadcom, Seedworm's Q1 2026 campaign marks a geographic expansion for a Middle East-focused MOIS platform, with the South Korean electronics intrusion likely reflecting Tehran's interest in semiconductor IP. Operators built redundancy into credential operations: SAM hive extraction, Kerberos TGT harvesting via GSS-API delegation abuse, and credential dialog spoofing, anticipating that endpoint controls would block some techniques. Sideloading through a signed SentinelOne binary exploits defender trust in security-product processes; the shift from Deno to Node.js signals runtime rotation to frustrate behavioral detection. Exfiltration through sendit[.]sh follows documented Iranian tradecraft blending stolen data into consumer file-sharing traffic. The campaign's geographic breadth may instead reflect loosely directed contractor activity under nominal MOIS oversight, implying opportunistic rather than strategic targeting.
4 sources
- Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign -
Symantec/SECURITY.COM - Iranian hackers targeted major South Korean electronics maker -
BleepingComputer - Symantec uncovers Iran-linked Seedworm espionage campaign targeting airport, government, manufacturing sectors -
Industrial Cyber - Iran-Linked Hackers Breached Major Korean Electronics Maker in Global Espionage Campaign -
Broadcom