MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
MuddyWater hit at least nine organizations in nine countries using DLL side-loading, signed binaries, and Node.js loaders to steal data and credentials.
Intelligence analysis by GPT-5.4 Mini

Broadcom says the Iran-linked MuddyWater group ran a stealthier espionage wave in early 2026, abusing signed software and DLL side-loading to drop malware, steal browser data, and gather credentials across victims in nine countries.
A hacking group called MuddyWater was sneaking into company computers in different countries. It used trusted programs like a thief wearing a delivery uniform, so the bad code looked normal at first.
Once inside, it tried to grab passwords, browser cookies, and other useful files. It also used scripts to look around the computer, take screenshots, and open secret tunnels for stolen data.
Think of it like someone hiding a tiny radio inside a real flashlight. The flashlight looks harmless, but the hidden radio lets the person send messages and listen in without being noticed.
Analysis
Campaign overview
Broadcom’s Symantec and Carbon Black teams attribute a new early-2026 espionage wave to the Iranian group MuddyWater. They say the activity affected at least nine organizations in nine countries across four continents, with targets including industrial and electronics manufacturing, education, public-sector bodies, financial services, and professional services.
How the intrusions worked
The operators leaned on DLL side-loading to hide malicious code inside legitimate, signed software. Two of the binaries called out in the report were Fortemedia’s fmapp.exe and SentinelOne’s sentinelmemoryscanner.exe. In both cases, the trusted executable was used to load a rogue DLL that then connected to attacker infrastructure or launched further tooling. One DLL was linked to an attacker-controlled IP address, while the other was designed to sideload sentinelagentcore.dll.
Those DLLs embedded ChromElevator, an open-source tool used to extract passwords, cookies, and payment card data from Chromium-based browsers. The report says this approach helps get around App-Bound Encryption protections. The intrusion chain also used Node.js scripts to start PowerShell code for discovery and data collection. According to the researchers, one node.exe implant chain handled reconnaissance, screenshot capture, SAM hive theft, privilege escalation, and SOCKS5 reverse-proxy tunneling.
Operational signs and victimology
The attackers also staged stolen data on sendit[.]sh in at least one case. In the South Korean electronics manufacturer intrusion, MuddyWater is believed to have repeated PowerShell reconnaissance and relaunched the side-loading binaries to maintain access. The initial entry method for that victim remains unknown. The researchers describe the activity as more disciplined and quieter than earlier MuddyWater operations.
The article also places the campaign alongside wider Iran-linked cyber activity, including sanctions against Emennet Pasargad and separate exfiltration and destructive operations tied to Iran’s Ministry of Intelligence and Security. Taken together, the reporting suggests a broader ecosystem of Iranian cyber operations that mixes espionage, credential theft, and infrastructure abuse.
Key points
- MuddyWater was linked to a campaign affecting at least nine organizations in nine countries across four continents.
- The group used DLL side-loading with legitimately signed binaries to run malicious code while posing as benign software.
- The malware chain included ChromElevator to steal browser data such as passwords, cookies, and payment card information.
- Node.js and PowerShell were used for reconnaissance, screenshot capture, credential theft, privilege escalation, and SOCKS5 tunneling.
- The researchers say the campaign reflects quieter and more disciplined operations than earlier MuddyWater activity.



