Iranian hackers targeted major South Korean electronics maker
ID: e8a239c1-cd4e-5248-8aa2-5c1d12652e18
STIX ID: report--e8a239c1-cd4e-5248-8aa2-5c1d12652e18
Feed Name: Bleeping Computer
Symantec researchers attribute a broad cyber‑espionage campaign to the Iran-linked APT MuddyWater (Seedworm), which compromised at least nine high‑profile organizations across multiple sectors and countries in February 2026. The campaign used DLL sideloading of legitimate signed binaries (fmapp.exe, sentinelmemoryscanner.exe) to load malicious DLLs containing the ChromElevator infostealer, leveraged PowerShell and Node.js loaders for payload control, conducted credential and registry hive theft, abused Kerberos, established persistence via registry changes, and exfiltrated data using public file‑sharing (sendit.sh); defenders should treat this as an intelligence-driven, high‑risk intrusion focused on industrial and government espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
