logo

Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign

ID: 09345c67-3244-5cfc-bb92-7e2462ec5ddd

STIX ID: report--09345c67-3244-5cfc-bb92-7e2462ec5ddd

Feed Name: security.com

Threat Score
88/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Threat Hunter Team

...
...

This report documents an early-2026 espionage campaign by the Iran-linked APT Seedworm that compromised at least nine organizations across multiple sectors and continents, using Node.js-orchestrated PowerShell implants and DLL sideloading of legitimately signed binaries (Fortemedia and SentinelOne) to run ChromElevator and other tools for credential theft, privilege escalation, SOCKS5 tunnelling, and data exfiltration via public file-transfer services; the document includes file hashes, IPs, domains, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.