Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and SentinelOne Binaries, ChromElevator Browser Theft, Node.js/PowerShell Implant Chain — Threadlinqs Intelligence
As of 2026-05-30, Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and SentinelOne Binaries, ChromElevator Browser Theft, Node.js/PowerShell Implant Chain is a high-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 49 indicators of compromise.
Threat ID: TL-2026-0500 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Iran-linked Seedworm (MuddyWater / Static Kitten / Temp Zagros — widely attributed to Iran's Ministry of Intelligence and Security, MOIS) ran a Q1 2026 espionage campaign hitting at least nine
Symantec's Threat Hunter Team disclosed on 12 May 2026 a multi-victim Seedworm (a.k.a. MuddyWater, Static Kitten, Temp Zagros) espionage campaign observed in the first quarter of 2026, spanning at least nine victim organizations across nine countries on four continents. Confirmed victim profiles include a major South Korean electronics manufacturer (week-long intrusion, 20–27 February 2026), Middle East government agencies, a Middle East international airport, Southeast Asian industrial manufacturers, a Latin American financial-services provider, and educational institutions in multiple countries. The campaign is consistent with MOIS-aligned strategic intelligence collection focused on high-tech manufacturing intellectual property, rival-government intelligence, and downstream service-provider access.
The defining tradecraft of this wave is DLL sideloading abuse of two legitimately signed, third-party Windows executables. The first pair — Fortemedia Inc.'s signed audio driver utility fmapp.exe paired with a malicious fmapp.dll — has prior reporting in Group-IB's MuddyWater telemetry. The second pair is notably new and provocative: SentinelOne's signed sentinelmemoryscanner.exe, a legitimate component of the SentinelOne endpoint product, was abused to sideload a malicious sentinelagentcore.dll. The operators' deliberate choice of a security-product binary is designed to defeat path- and signature-based detection, exhaust triage-analyst attention through false 'security product activity' attribution, and complicate evidence collection on managed endpoints. Both malicious DLLs delivered ChromElevator, a publicly available post-exploitation tool that covertly extracts and exfiltrates passwords, cookies, and payment-card data from Chromium-based browsers (Chrome, Edge, Brave, Opera, etc.).
In every observed instance the sideloaded executables ran under node.exe (the Node.js runtime) as parent or grandparent process, indicating that a Node.js loader script (a previously unattested tactical shift from the group's earlier reliance on the Deno runtime) drove execution rather than a human operator. A Node.js script was recovered embedded inside an XML file on the victim host. From that loader, the operators issued PowerShell stages downloaded from a hard-coded plaintext-HTTP staging server at 179.43.177[.]220:8080 and from a fallback attacker-owned domain timetrakr[.]cloud. Files observed being fetched include nm.ps1, a.dat (suspected encoded payload), a.exe (suspected Windows binary), sp.ps1 (screenshot capture), and lpu.dll (a PowerShell module despite the .dll extension). curl.exe was used for several downloads to keep network artefacts out of PowerShell's script-block logs.
The Korean intrusion timeline began on 20 February 2026 with a tight burst of PowerShell reconnaissance (whoami, whoami /all, hostname, ipconfig /all, net session, net user /domain, net group <REMOVED> /domain) followed by a WMI antivirus enumeration (wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get *), automated screenshot capture, ipinfo.io/json public-IP discovery, the first DLL sideload pair (fmapp.exe + fmapp.dll), then a second pair (sentinelmemoryscanner.exe + sentinelagentcore.dll) approximately fifteen minutes later. Persistence was installed via an HKCU\Software\Microsoft\Windows\CurrentVersion\Run value with a randomly generated name pointing at the sideloaded binary. Credential dumping proceeded through SAM/SECURITY/SYSTEM hive theft (reg save hklm\sam | security | system to C:\Windows\Temp), execution of a privilege-escalation binary (SHA256 74ab3838... — automated Kerberos TGT extraction via GSS-API delegation abuse to obtain a usable ticket from a high-privilege account without password knowledge), and two further credential stealers, including a credential harvester (d587959841... ) that calls CredUIPromptForWindowsCredentialsW to spoof a Windows credential dialog and persists captured passwords to C:\ProgramData\lopa.txt. Impla
Weaknesses (CWE)
CWE-426, CWE-427, CWE-829, CWE-732
Target sectors: industrial manufacturing, electronics manufacturing, education, public sector, government agencies, financial services, professional services, transportation (aviation)
Target regions: East Asia, South Korea, Southeast Asia, Middle East, Latin America, Europe, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 49 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1590, T1583.001, T1583.004, T1588.002, T1588.003, T1190, T1566, T1059.001, T1059.003, T1059.007