logo

Seedworm APT Abuses Signed Fortemedia and SentinelOne Binaries for DLL Sideloading

ID: c83f6cca-07ea-5c3d-9949-51b53590d21c

STIX ID: report--c83f6cca-07ea-5c3d-9949-51b53590d21c

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Tushar Subhra Dutta

...
...

Symantec reports an early‑2026 espionage campaign attributed to Iran‑linked Seedworm that compromised at least nine organizations across multiple industries and continents by abusing legitimate signed executables for DLL sideloading (fmapp.exe and sentinelmemoryscanner.exe) to load ChromElevator and credential theft tools; the attackers used an embedded Node.js runtime to orchestrate actions, established persistence via startup registry entries, and exfiltrated data using a public file-transfer service, with the report providing IoCs (hashes, IPs, domains, URLs) and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.