Seedworm Expands Operations with Stealth-Focused Espionage Campaign
ID: 05514010-aed9-52d2-8a91-29381b7b1b16
STIX ID: report--05514010-aed9-52d2-8a91-29381b7b1b16
Feed Name: ThreatMon
ThreatMon researchers identified a stealthy espionage campaign attributed to the Iran-aligned Seedworm (MuddyWater/Static Kitten) targeting organizations across manufacturing, finance, government, aviation, and education. Attackers prioritized operational security by abusing legitimate tooling: using signed third-party executables for DLL sideloading, executing payloads via Node.js to reduce PowerShell visibility, harvesting credentials (registry hives, browser-stored credentials, Kerberos delegation abuse, fake Windows prompts), and exfiltrating stolen files through public file-sharing services via curl.exe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
