Seedworm APT Abuses Signed Binaries for DLL Sideloading
ID: ca5876bd-5ca4-5b24-bbb3-abd8bebc53a4
STIX ID: report--ca5876bd-5ca4-5b24-bbb3-abd8bebc53a4
Feed Name: GBHackers
**Seedworm (MuddyWater) conducted a stealthy, multi‑continent cyber‑espionage campaign in early 2026 targeting high‑value organizations across manufacturing, government, education, finance, and aviation.** The group abused legitimately signed Fortemedia and SentinelOne binaries to sideload malicious DLLs (including a ChromElevator infostealer), used Node.js as an orchestration parent process to deliver PowerShell reconnaissance and credential‑harvesting scripts, leveraged Kerberos delegation for TGT theft, and exfiltrated data via public file‑sharing (sendit.sh); the report includes hashes, IPs, domains, and a Feb 20–27 intrusion timeline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
