{"id":256033,"date":"2026-05-26T11:48:00","date_gmt":"2026-05-26T15:48:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/26\/muddywater-uses-dll-side-loading-in-espionage-campaign-targeting-9-countries\/"},"modified":"2026-05-26T13:30:12","modified_gmt":"2026-05-26T17:30:12","slug":"muddywater-uses-dll-side-loading-in-espionage-campaign-targeting-9-countries","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/26\/muddywater-uses-dll-side-loading-in-espionage-campaign-targeting-9-countries\/","title":{"rendered":"MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/muddywater-uses-dll-side-loading-in.html\">MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/muddywater-uses-dll-side-loading-in.html\">https:\/\/thehackernews.com\/2026\/05\/muddywater-uses-dll-side-loading-in.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-26 11:48:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p>The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026.<\/p>\n<p>The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services, per the Threat Hunter Team from Symantec and Carbon Black. Among the victims is a major South Korean electronics manufacturer, with the attackers spending a week inside its network in February 2026.<\/p>\n<p>Also singled as part of the sprawling espionage effort were an international airport in the Middle East, Southeast Asian industrial manufacturers, and a Latin American financial-services provider.<\/p>\n<p>&#8220;The attackers relied heavily on DLL side-loading using legitimately signed Fortemedia (fmapp.exe) and SentinelOne (sentinelmemoryscanner.exe) binaries to execute malicious DLLs while masquerading as benign software,&#8221; Broadcom&#8217;s cybersecurity teams said.<\/p>\n<p>The use of &#8220;fmapp.exe&#8221; to sideload &#8220;fmapp.dll&#8221; was previously documented by Group-IB in connection with another MuddyWater campaign codenamed Operation Olalampo. According to Huntress, the DLL contains code to connect to an attacker-controlled IP address (&#8220;157.20.182[.]49&#8221;).<\/p>\n<p>On the other hand, the abuse of &#8220;sentinelmemoryscanner.exe&#8221; &#8211; a binary associated with a security product &#8211; is assessed to be a deliberate choice, as it can bypass signature-based detection. It&#8217;s designed to sideload a rogue DLL named &#8220;sentinelagentcore.dll.&#8221;<\/p>\n<p>Both the DLLs embed an open-source tool called ChromElevator to siphon passwords, cookies, and payment card data from Chromium-based browsers, effectively getting around App-Bound Encryption (ABE) protections.<\/p>\n<p>A noteworthy aspect of the attacks is the use of Node.js scripts to launch PowerShell code responsible for carrying out discovery and information gathering operations. In at least one instance, the attackers have been found to stage the stolen data on&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/muddywater-uses-dll-side-loading-in.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries https:\/\/thehackernews.com\/2026\/05\/muddywater-uses-dll-side-loading-in.html Publish Date: 2026-05-26 11:48:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":256035,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgkb692n4xA8jDUKZCkwPSIXqiyTaEk_bQhrNaZj33tRhusSP40-iwlk5x7iblb9M63WKWVbj8Gm6oPJZY3bm602-qFyLLnRXuCKsl40iAZG_5-ehqlQ4CYaO442hgo4FBKrspLCO4r_ET1U4U3fPCKCYOc7DFuDn_mv7ZzbzH_IC0NAt2HVVSxwIBNOruk\/s1600\/cyber-espionage.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24],"class_list":["post-256033","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/256033"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=256033"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/256033\/revisions"}],"predecessor-version":[{"id":256037,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/256033\/revisions\/256037"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/256035"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=256033"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=256033"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=256033"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}