logo

Seedworm Expands Operations with Stealth-Focused Espionage Campaign

ID: 05514010-aed9-52d2-8a91-29381b7b1b16

STIX ID: report--05514010-aed9-52d2-8a91-29381b7b1b16

Feed Name: ThreatMon

Threat Score
90/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: admin

...
...

ThreatMon researchers identified a stealthy espionage campaign attributed to the Iran-aligned Seedworm (MuddyWater/Static Kitten) targeting organizations across manufacturing, finance, government, aviation, and education. Attackers prioritized operational security by abusing legitimate tooling: using signed third-party executables for DLL sideloading, executing payloads via Node.js to reduce PowerShell visibility, harvesting credentials (registry hives, browser-stored credentials, Kerberos delegation abuse, fake Windows prompts), and exfiltrating stolen files through public file-sharing services via curl.exe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.