logo

Iranian hackers targeted major South Korean electronics maker

ID: e8a239c1-cd4e-5248-8aa2-5c1d12652e18

STIX ID: report--e8a239c1-cd4e-5248-8aa2-5c1d12652e18

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-05-13

Date Updated: 2026-05-22

Author: Bill Toulas

...
...

Symantec researchers attribute a broad cyber‑espionage campaign to the Iran-linked APT MuddyWater (Seedworm), which compromised at least nine high‑profile organizations across multiple sectors and countries in February 2026. The campaign used DLL sideloading of legitimate signed binaries (fmapp.exe, sentinelmemoryscanner.exe) to load malicious DLLs containing the ChromElevator infostealer, leveraged PowerShell and Node.js loaders for payload control, conducted credential and registry hive theft, abused Kerberos, established persistence via registry changes, and exfiltrated data using public file‑sharing (sendit.sh); defenders should treat this as an intelligence-driven, high‑risk intrusion focused on industrial and government espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.