logo

Seedworm APT Abuses Signed Binaries for DLL Sideloading

ID: ca5876bd-5ca4-5b24-bbb3-abd8bebc53a4

STIX ID: report--ca5876bd-5ca4-5b24-bbb3-abd8bebc53a4

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Mayura Kathir

...
...

**Seedworm (MuddyWater) conducted a stealthy, multi‑continent cyber‑espionage campaign in early 2026 targeting high‑value organizations across manufacturing, government, education, finance, and aviation.** The group abused legitimately signed Fortemedia and SentinelOne binaries to sideload malicious DLLs (including a ChromElevator infostealer), used Node.js as an orchestration parent process to deliver PowerShell reconnaissance and credential‑harvesting scripts, leveraged Kerberos delegation for TGT theft, and exfiltrated data via public file‑sharing (sendit.sh); the report includes hashes, IPs, domains, and a Feb 20–27 intrusion timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.