HomeSecurityEspionage: MuddyWater targeted 9 organizations

Espionage: MuddyWater targeted 9 organizations

Iranian hackers MuddyWater have been linked to a new campaign that affected at least nine organizations in nine countries. The attacks took place during the first quarter of 2026.

MuddyWater Spying

The activity targeted the following sectors: industrial and electronics manufacturing, education, government agencies, financial services , and professional services, according to the Threat Hunter team from Symantec and Carbon Black. Among the victims is a major South Korean electronics manufacturer, with the attackers spending a week inside its network in February 2026.

Also targeted were an international airport in the Middle East , industrial manufacturers in Southeast Asia , and a financial services provider in Latin America .

See also: Megalodon attack on GitHub targeted 5,561 repositories with malicious CI/CD

MuddyWater: What methods did the team use in the recent campaign?

“ The attackers relied heavily on DLL side-loading using legitimately signed Fortemedia (fmapp.exe) and SentinelOne (sentinelmemoryscanner.exe) binaries to execute malicious DLLs while masquerading as innocent software ,” Broadcom’s cybersecurity teams said

The use of “fmapp.exe” to sideload “fmapp.dll” was previously documented by Group-IB in connection with another MuddyWater campaign codenamed Operation Olalampo. According to Huntress, the DLL contains code to connect to an IP address controlled by the attacker (“157.20.182[.]49”).

The misuse of “sentinelmemoryscanner.exe” – a binary bundled with a security product – is believed to be a deliberate choice, as it can bypass signature-based detection . It is designed to load a malicious DLL named “sentinelagentcore.dll.”

See also: Laravel-Lang: Supply chain attack with credential stealing malware

Espionage: MuddyWater targeted 9 organizations

Both DLLs incorporate an open-source tool called ChromElevator for extracting passwords, cookies, and payment data from Chromium-based browsers (effectively bypassing App-Bound Encryption protections).

A notable element of the attacks is the use of Node.js scripts to execute PowerShell code responsible for performing discovery and information gathering. In at least one case, the attackers were found to be storing the stolen data on sendit[.]sh, a public file transfer service.

“A node.exe-based implant chain was used to drop PowerShell scripts that performed reconnaissance, screenshot capture, SAM hive theft, privilege escalation, and SOCKS5 reverse-proxy tunneling,” Symantec and Carbon Black said.

The two aforementioned DLL side-loading pairs were also delivered to provide attackers with a hidden tunnel to carry traffic and launch ChromElevator. The attacks are characterized by attempts to dump credentials that would allow lateral traffic on networks.

In the attack targeting the South Korean electronics manufacturer, MuddyWater is believed to have repeatedly performed PowerShell-based reconnaissance and re-executed the two binaries to ensure it maintained access to the compromised computer. The initial access vector used to breach the organization is unknown.

See also: Kimwolf Botnet: Its 23-year-old creator arrested

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Espionage: MuddyWater targeted 9 organizations

MuddyWater: More effective attacks

“The frequency is again consistent with implant-driven activity rather than continuous operator presence,” the researchers noted. “The campaign history shows a clear move toward quieter, more disciplined operations. None of these techniques are groundbreaking, but together they provide further evidence of a significant step up in MuddyWater’s operational hygiene.”

Overall, MuddyWater’s new campaign reflects the growing maturity and operational discipline of Iranian cyberespionage groups. While the techniques used — such as DLL side-loading, the misuse of legitimate binaries, and the use of PowerShell for reconnaissance and credential dumping — are not considered groundbreaking individually, their combination creates a highly effective and difficult-to-detect attack framework. The emphasis on maintaining access, moving silently within networks, and stealing credentials suggests that attackers are now investing more in long-term persistence and low-profile activity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS