PULSE NAME
Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
WHITE MuddyWater AlienVault 2026-05-12 Modified: 2026-05-12
17
IOCs
MEDIUM VOLUME
Iranian state-sponsored threat group Seedworm conducted a widespread espionage campaign in early 2026, compromising at least nine organizations across nine countries on four continents. Victims included a major South Korean electronics manufacturer, government agencies, an international airport in the Middle East, Southeast Asian industrial manufacturers, a Latin American financial services provider, and educational institutions. The attackers utilized DLL sideloading techniques with legitimately signed Fortemedia and SentinelOne binaries to execute malicious payloads, deployed Node.js-based implants for orchestration, and employed multiple PowerShell scripts for reconnaissance, credential theft, and privilege escalation. Data exfiltration was conducted through public file-transfer service sendit.sh to blend malicious traffic with legitimate cloud services. The campaign demonstrates Seedworm's evolved tradecraft and expanded targeting beyond traditional Middle Eastern focus areas.
Indicators of Compromise (17)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2533307ec1ef8b0611c8896e1460b076 2026-05-12
FileHash-MD5 da52c20a56cca22ad994a1f3baa8b3bd 2026-05-12
FileHash-SHA1 2f5166086da5a57d7e59a767a54ed6fe9a6db444 2026-05-12
FileHash-SHA1 324918c73b985875d5f974da3471f2a0a4874687 2026-05-12
FileHash-SHA256 0c9b911935a3705b0ad569446804d80026feb6db3884aeb240b6c76e9b8cf139 2026-05-12
FileHash-SHA256 128b58a2a2f1df66c474094aacb7e50189025fbf45d7cd8e0834e93a8fbed667 2026-05-12
FileHash-SHA256 3ee7dab4ae4f6d4f16dfabb6f38faef370411a9fc00ff035844e54703b99600a 2026-05-12
FileHash-SHA256 74ab3838ebed7054b2254bf7d334c80c8b2cfec4a97d1706723f8ea55f11061f 2026-05-12
FileHash-SHA256 b21c802775df0c0d82c8cfde299084abc624898b10258db641b820172a0ba29a 2026-05-12
FileHash-SHA256 bee79c3302b1a7afc0952842d14eff83a604ef00bfdae525176c16c80b2045f7 2026-05-12
FileHash-SHA256 c6182fd01b14d84723e3c9d11bc0e16b34de6607ccb8334fc9bb97c1b44f0cde 2026-05-12
FileHash-SHA256 d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc 2026-05-12
FileHash-SHA256 e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b 2026-05-12
URL https://svc.wompworthy.com 2026-05-12
URL https://timetrakr.cloud/sp.ps1' 2026-05-12
domain timetrakr.cloud 2026-05-12
hostname svc.wompworthy.com 2026-05-12