logo

Stealth & Automation: Seedworm’s 2026 Global Campaign Hijacks Security Software to Deploy ChromElevator

ID: d00a17ae-c60a-52d0-8083-5feedfbed393

STIX ID: report--d00a17ae-c60a-52d0-8083-5feedfbed393

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

Threat intelligence reports a 2026 espionage campaign attributed to Iran-linked Seedworm (Muddy Water) that infiltrated at least nine organizations across four continents. The actors shifted to quieter, automated operations using DLL sideloading of legitimately signed binaries (including Fortemedia's fmapp.exe and SentinelOne's sentinelmemoryscanner.exe) to load the ChromElevator infostealer; a Node.js-based loader automated reconnaissance, credential theft, and lateral movement; and stolen data was exfiltrated via a public file-transfer service (sendit.sh) to blend with normal cloud traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.