logo

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

ID: f8c2ba2d-b439-5a79-aaa5-af97bdb3ec91

STIX ID: report--f8c2ba2d-b439-5a79-aaa5-af97bdb3ec91

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-26

Date Updated: 2026-06-21

Author: [email protected] (The Hacker News)

...
...

Symantec, Carbon Black, Broadcom and other researchers attribute a coordinated early‑2026 espionage and exfiltration campaign to Iran-linked operators (notably MuddyWater/Seedworm and MOIS-affiliated actors). The adversaries used DLL side‑loading of signed Fortemedia and SentinelOne binaries to run malicious DLLs (including ChromElevator) that exfiltrate browser credentials and payment data, Node.js/PowerShell implant chains for reconnaissance and lateral movement, and bespoke tools (FileFiend) and public file services to stage stolen data; some U.S. victims also experienced destructive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.