----------------
🎯 Threat Intelligence: Seedworm (MuddyWater) Q1 2026 Espionage Campaign
===================
Iran-linked espionage group Seedworm (aka MuddyWater, Temp Zagros, Static Kitten), attributed to Iran's MOIS, conducted a broad campaign in Q1 2026. At least nine organizations across nine countries on four continents were compromised, including a major South Korean electronics manufacturer (operators persisted for a full week in February 2026), a Middle Eastern international airport, government agencies, Southeast Asian industrial manufacturers, a Latin American financial-services provider, and educational institutions. Every target held information of intelligence value to Tehran.
🔹 Technical Details
The campaign relied on DLL sideloading with two pairs of legitimate, signed binaries:
1. Fortemedia fmapp.exe / fmapp.dll: Legitimate audio-driver utility abused to sideload a malicious DLL. Previously documented by Group-IB in Seedworm reporting.
2. SentinelOne sentinelmemoryscanner.exe / sentinelagentcore.dll: Legitimate, signed endpoint component abused to sideload malicious code. Using a security-product binary defeats path and signature-based detection and confuses triage.
Both malicious DLLs contain ChromElevator, a publicly available post-exploitation tool that steals passwords, cookies, and payment card data from Chromium-based browsers.
In both cases, node.exe was the parent process at execution time, indicating the sideloading was orchestrated by a Node.js script rather than user execution. A Node.js script was found embedded in an XML file on targeted hosts.
🔹 Analysis
This campaign reflects a tactical shift. Seedworm has historically been a prolific PowerShell user, but here PowerShell was delivered and orchestrated through Node.js. The group's previous campaign used Deno. This experimentation with scripting runtimes is likely an evasion measure.
Multiple credential theft and privilege escalation tools were deployed iteratively, suggesting operators worked through their toolkit searching for viable paths to elevated access. One credential harvester (SHA256: d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc) calls CredUIPromptForWindowsCredentialsW, triggering the standard Windows credential prompt to harvest credentials.
PowerShell scripts pulled from a staging server performed reconnaissance, screenshot capture, SAM hive theft, and SOCKS5 reverse-proxy tunnelling.
🔹 Attack Chain Analysis
• Initial Access: Not detailed in source
• Execution: Node.js scripts embedded in XML files orchestrate payload delivery
• Persistence: DLL sideloading via legitimate signed binaries
• Credential Access: ChromElevator for browser data; CredUIPromptForWindowsCredentialsW harvester
• Privilege Escalation: Iterative deployment of multiple escalation tools
• Collection: Screenshot capture, SAM hive theft
• C2: SOCKS5 reverse-proxy tunnelling
🔹 Detection
• Hunt for node.exe as parent of unexpected processes, especially those loading signed binaries from non-standard paths
• Flag DLL sideloading patterns: fmapp.dll and sentinelagentcore.dll loaded from unusual locations
• Monitor for CredUIPromptForWindowsCredentialsW calls from suspicious processes
• Review SentinelOne and Fortemedia binary execution paths for anomalies
🔹 Limitations
Source does not specify the initial access vector. Attribution to MOIS is described as "widely believed" rather than definitively confirmed. Campaign scope may exceed the nine confirmed organizations.
🔹 seedworm #muddywater #threatintelligence #dllsideloading #iran
🔗 Source: https://www.security.com/threat-intelligence/iran-seedworm-electronics