Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    15 AI Security Lessons From Black Hat and Ai4 2026

    August 8, 2026

    The LLM Era Changed How B2B Decision-Makers Purchase, And It’s Time Marketing Caught Up

    August 8, 2026

    Indyx review: Wardrobe apps say they’ll help you shop less. Do they overpromise?

    August 7, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
    Cybersecurity

    MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

    InfoForTechBy InfoForTechMay 27, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026.

    The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services, per the Threat Hunter Team from Symantec and Carbon Black. Among the victims is a major South Korean electronics manufacturer, with the attackers spending a week inside its network in February 2026.

    Also singled as part of the sprawling espionage effort were an international airport in the Middle East, Southeast Asian industrial manufacturers, and a Latin American financial-services provider.

    “The attackers relied heavily on DLL side-loading using legitimately signed Fortemedia (fmapp.exe) and SentinelOne (sentinelmemoryscanner.exe) binaries to execute malicious DLLs while masquerading as benign software,” Broadcom’s cybersecurity teams said.

    The use of “fmapp.exe” to sideload “fmapp.dll” was previously documented by Group-IB in connection with another MuddyWater campaign codenamed Operation Olalampo. According to Huntress, the DLL contains code to connect to an attacker-controlled IP address (“157.20.182[.]49”).

    On the other hand, the abuse of “sentinelmemoryscanner.exe” – a binary associated with a security product – is assessed to be a deliberate choice, as it can bypass signature-based detection. It’s designed to sideload a rogue DLL named “sentinelagentcore.dll.”

    Both the DLLs embed an open-source tool called ChromElevator to siphon passwords, cookies, and payment card data from Chromium-based browsers, effectively getting around App-Bound Encryption (ABE) protections.

    A noteworthy aspect of the attacks is the use of Node.js scripts to launch PowerShell code responsible for carrying out discovery and information gathering operations. In at least one instance, the attackers have been found to stage the stolen data on sendit[.]sh, a public file-transfer service.

    “A node.exe-based implant chain was used to drop PowerShell scripts that performed reconnaissance, screenshot capture, SAM hive theft, privilege escalation, and SOCKS5 reverse-proxy tunnelling,” Symantec and Carbon Black said.

    Also delivered are the two aforementioned DLL side-loading pairs to provide attackers with a covert tunnel to relay traffic and launch ChromElevator. The attacks are also characterized by efforts to dump credentials that would allow them to move laterally across the networks.

    In the intrusion targeting the South Korean electronics manufacturer, MuddyWater is believed to have repeatedly carried out PowerShell-based reconnaissance, as well as re-execute the two binaries to ensure it retains access to the compromised host. The initial access vector used to breach the organization is unknown.

    “The cadence is again consistent with implant-driven activity rather than continuous operator presence,” the researchers said. “Its campaign history shows a clear move towards quieter, more disciplined operations. None of these techniques is individually novel, but in combination they provide more evidence of a significant step up in operational hygiene from the Seedworm that we knew of two or three years ago.”

    The development comes as the European Council imposed sanctions against Iranian company Emennet Pasargad for hacking a Swedish SMS service, accessing the contents of a French subscriber database and putting it up for sale, and for spreading disinformation via compromised advertising billboards during the 2024 Paris Olympic Games.

    The company, per the U.S. State Department, goes by the name Shahid Shushtari and is affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). It’s tracked under the monikers Cobalt Obelisk, Cotton Sandstorm, Haywire Kitten (formerly ChaoticOrchestra), Marnanbridge, and UNC5866.

    “Shahid Shushtari members have caused significant financial damage and disruption to U.S. businesses and government agencies through coordinated cyber and cyber-enabled information operations,” the State Department noted in December 2025. “These campaigns have targeted multiple critical infrastructure sectors, including news, shipping, travel, energy, financial, and telecommunications in the United States, Europe, and the Middle East.”

    Iran-backed hackers have also been tied to an exfiltration campaign aimed at organizations in the U.S., Israel, Saudi Arabia, and Turkey between late March and early April 2026, with at least two U.S. victims also targeted by destructive operations, such as deletion of partitions and data backups.

    Although these incidents were claimed by a pro-Iranian persona named Ababil of Minab, a new analysis from Gambit Security has tied the campaign infrastructure to Iran’s Ministry of Intelligence and Security (MOIS).

    Other targets include an Israeli organization in the media sector, an Israeli higher education institution, a Turkish insurance brokerage, and several additional websites across the restaurant, culture, digital services, and news sectors.

    No destructive activity has been observed against these victims. In these cases, the adversary has been found to employ a bespoke C++ file collection and exfiltration tool internally codenamed FileFiend.

    “The binary could enumerate local drives and SMB shares, walk the file system, and send files to a hard-coded C2 [command-and-control] server,” Gambit Security researchers Eyal Sela and Nir Varon said in a report published today.

    Alternatively, data of interest is compressed into RAR archives on a host inside the victim environment and uploaded to the organization’s public website at the web root, from where they are extracted using the Axel command-line download accelerator and tunneled through proxychains.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    15 AI Security Lessons From Black Hat and Ai4 2026

    August 8, 2026

    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    August 7, 2026

    ChatGPT Atlas Shuts Down Aug. 9: What Users Must Save Before Migrating

    August 7, 2026

    CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

    August 6, 2026

    Apple briefly removes Telegram from App Store over reported CSAM violation

    August 6, 2026

    Detect East-West Traffic Threats with Fidelis Network

    August 5, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.