discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

MuddyWater hit at least nine organizations in nine countries using DLL side-loading, signed binaries, and Node.js loaders to steal data and credentials.

By Ravie Lakshmanan·May 26·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
Image: thehackernews.com

Broadcom says the Iran-linked MuddyWater group ran a stealthier espionage wave in early 2026, abusing signed software and DLL side-loading to drop malware, steal browser data, and gather credentials across victims in nine countries.

Why it matters

This is a broad, multi-country espionage campaign that shows how state-linked actors keep refining access and stealth. It also shows defenders how trusted binaries, browser data theft, and PowerShell chains are being combined in one intrusion path.

A hacking group called MuddyWater was sneaking into company computers in different countries. It used trusted programs like a thief wearing a delivery uniform, so the bad code looked normal at first.

Once inside, it tried to grab passwords, browser cookies, and other useful files. It also used scripts to look around the computer, take screenshots, and open secret tunnels for stolen data.

Think of it like someone hiding a tiny radio inside a real flashlight. The flashlight looks harmless, but the hidden radio lets the person send messages and listen in without being noticed.

Analysis

Campaign overview

Broadcom’s Symantec and Carbon Black teams attribute a new early-2026 espionage wave to the Iranian group MuddyWater. They say the activity affected at least nine organizations in nine countries across four continents, with targets including industrial and electronics manufacturing, education, public-sector bodies, financial services, and professional services.

How the intrusions worked

The operators leaned on DLL side-loading to hide malicious code inside legitimate, signed software. Two of the binaries called out in the report were Fortemedia’s fmapp.exe and SentinelOne’s sentinelmemoryscanner.exe. In both cases, the trusted executable was used to load a rogue DLL that then connected to attacker infrastructure or launched further tooling. One DLL was linked to an attacker-controlled IP address, while the other was designed to sideload sentinelagentcore.dll.

Those DLLs embedded ChromElevator, an open-source tool used to extract passwords, cookies, and payment card data from Chromium-based browsers. The report says this approach helps get around App-Bound Encryption protections. The intrusion chain also used Node.js scripts to start PowerShell code for discovery and data collection. According to the researchers, one node.exe implant chain handled reconnaissance, screenshot capture, SAM hive theft, privilege escalation, and SOCKS5 reverse-proxy tunneling.

Operational signs and victimology

The attackers also staged stolen data on sendit[.]sh in at least one case. In the South Korean electronics manufacturer intrusion, MuddyWater is believed to have repeated PowerShell reconnaissance and relaunched the side-loading binaries to maintain access. The initial entry method for that victim remains unknown. The researchers describe the activity as more disciplined and quieter than earlier MuddyWater operations.

The article also places the campaign alongside wider Iran-linked cyber activity, including sanctions against Emennet Pasargad and separate exfiltration and destructive operations tied to Iran’s Ministry of Intelligence and Security. Taken together, the reporting suggests a broader ecosystem of Iranian cyber operations that mixes espionage, credential theft, and infrastructure abuse.

Key points

  • MuddyWater was linked to a campaign affecting at least nine organizations in nine countries across four continents.
  • The group used DLL side-loading with legitimately signed binaries to run malicious code while posing as benign software.
  • The malware chain included ChromElevator to steal browser data such as passwords, cookies, and payment card information.
  • Node.js and PowerShell were used for reconnaissance, screenshot capture, credential theft, privilege escalation, and SOCKS5 tunneling.
  • The researchers say the campaign reflects quieter and more disciplined operations than earlier MuddyWater activity.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityglobal-newsresearchtech

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

May 26, 2026

Source

thehackernews.com

Share

Topics

securityglobal-newsresearchtech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…