Threats Feed|Seedworm|Last Updated 15/05/2026|AuthorCertfa Radar|Publish Date12/05/2026

Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Downloader,Dropper,Spyware
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.

Detected Targets

TypeDescriptionConfidence
SectorFinancial
Verified
SectorGovernment Agencies and Services
Verified
SectorManufacturing
Verified
SectorProfessional Service
Verified
SectorAerospace
Verified
SectorEducation
Verified
SectorTransportation
Verified
RegionSouth Korea
Verified
RegionMiddle East Countries
Verified

Extracted IOCs

  • timetrakr[.]cloud
  • svc.wompworthy[.]com
  • 0c9b911935a3705b0ad569446804d80026feb6db3884aeb240b6c76e9b8cf139
  • 128b58a2a2f1df66c474094aacb7e50189025fbf45d7cd8e0834e93a8fbed667
  • 3ee7dab4ae4f6d4f16dfabb6f38faef370411a9fc00ff035844e54703b99600a
  • 74ab3838ebed7054b2254bf7d334c80c8b2cfec4a97d1706723f8ea55f11061f
  • b21c802775df0c0d82c8cfde299084abc624898b10258db641b820172a0ba29a
  • bee79c3302b1a7afc0952842d14eff83a604ef00bfdae525176c16c80b2045f7
  • c6182fd01b14d84723e3c9d11bc0e16b34de6607ccb8334fc9bb97c1b44f0cde
  • d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc
  • e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b
  • 104[.]21.48.205
  • 172[.]67.156.47
  • 178[.]128.233.36
  • 179[.]43.177.220
  • 34[.]117.59.81
  • 37[.]187.78.41
  • hxxp://179[.]43.177.220:8080/a[.]dat
  • hxxp://179[.]43.177.220:8080/a[.]exe
  • hxxp://179[.]43.177.220:8080/nm[.]ps1
  • hxxps://svc.wompworthy[.]com
download

Tip: 21 related IOCs (6 IP, 2 domain, 4 URL, 0 email, 9 file hash) to this threat have been found.

Overlaps

MuddyWaterUnmasking Iranian Cyber Operations: Threat Actors Target Global Critical Infrastructure

Source: Hunt.io - March 2026

Detection (one case): e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Seedworm Global Espionage Campaign FAQ

In early 2026, a highly disciplined espionage group successfully breached multiple organizations worldwide, including a major South Korean electronics manufacturer. The attackers maintained undetected access inside networks for extended periods to quietly gather intelligence and steal sensitive information.

The attacks were carried out by a well-known cyber espionage group called Seedworm, which is also tracked under the name MuddyWater. This threat group is widely believed by intelligence analysts to be linked to the Iranian Ministry of Intelligence and Security.

This was a deliberate intelligence-gathering operation rather than a destructive attack. The primary goal was to conduct espionage by stealing highly valuable information, such as intellectual property, research data, and intelligence on rival governments.

The campaign was widespread and sprawling. Based on current discoveries, it affected at least nine distinct organizations located across nine different countries, spanning four continents.

Yes, the attackers targeted a wide variety of specific sectors, including industrial and electronics manufacturing, education, public-sector bodies, and financial services. They specifically sought out networks that held high-value intelligence or provided downstream access to other businesses and customers.

The hackers used legitimate, trusted software programs (like audio drivers and security tools) to sneak their malicious tools into the systems undetected. Once inside, they used automated scripts to silently take screenshots, steal passwords, and tunnel data out of the network using public file-sharing websites.

These organizations hold material that is highly valuable to foreign intelligence services. This includes proprietary high-tech manufacturing details, sensitive global research, and extensive network accesses that can be used as stepping stones to breach other companies.

Organizations should strictly monitor their networks for the unusual use of common administrative tools and unexpected changes to startup settings. It is also vital to block access to unapproved public file-sharing services and train employees to report suspicious, unexpected password prompts on their computers.

While the overall campaign was global in its reach, the attacks themselves were highly targeted. The attackers specifically selected organizations that aligned with their intelligence requirements and carefully tailored their tools to evade detection inside those specific networks.

About Affiliation
Seedworm
Seedworm is Symantec's designation for the Iranian MOIS-linked threat cluster known as MuddyWater. Active since at least 2017, Symantec documented the group's targeting of government, energy, and telecommunications organizations across the Middle East and Central Asia. Seedworm operations use spear phishing to deliver custom backdoors including POWERSTATS and Canopy, with Symantec noting the group's rapid operational tempo — often pivoting from initial compromise to active data collection within hours. The cluster shares infrastructure, tooling, and targeting patterns with MuddyWater tracking across other vendors.
View Seedworm's Insights