PULSE NAME
Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
WHITE MuddyWater AlienVault 2026-05-12 Modified: 2026-05-12
17
IOCs
MEDIUM VOLUME
Iranian state-sponsored threat group Seedworm conducted a widespread espionage campaign in early 2026, compromising at least nine organizations across nine countries on four continents. Victims included a major South Korean electronics manufacturer, government agencies, an international airport in the Middle East, Southeast Asian industrial manufacturers, a Latin American financial services provider, and educational institutions. The attackers utilized DLL sideloading techniques with legitimately signed Fortemedia and SentinelOne binaries to execute malicious payloads, deployed Node.js-based implants for orchestration, and employed multiple PowerShell scripts for reconnaissance, credential theft, and privilege escalation. Data exfiltration was conducted through public file-transfer service sendit.sh to blend malicious traffic with legitimate cloud services. The campaign demonstrates Seedworm's evolved tradecraft and expanded targeting beyond traditional Middle Eastern focus areas.
Indicators of Compromise (2 / 17 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2533307ec1ef8b0611c8896e1460b076 2026-05-12
FileHash-MD5 da52c20a56cca22ad994a1f3baa8b3bd 2026-05-12