Iran-Linked Seedworm Escalates Global Espionage with Enhanced Node.js Tradecraft
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Downloader,Dropper,Spyware
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
In early 2026, the Iran-linked Seedworm group conducted a global espionage campaign targeting organizations across South Korea, the Middle East, Southeast Asia, and Latin America. Targeted sectors included electronics and industrial manufacturing, aviation, education, finance, and government agencies. Demonstrating a maturation in tradecraft, the attackers utilized Node.js scripts to orchestrate their operations, departing from their traditional reliance on raw PowerShell. The campaign heavily featured DLL sideloading, abusing legitimately signed Fortemedia and SentinelOne binaries to covertly deploy tools like ChromElevator for credential theft. Furthermore, the operators established SOCKS5 reverse proxies and blended their network traffic by exfiltrating stolen data through public file-transfer services, showcasing enhanced operational hygiene and evasion techniques.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Financial | Verified |
| Sector | Government Agencies and Services | Verified |
| Sector | Manufacturing | Verified |
| Sector | Professional Service | Verified |
| Sector | Aerospace | Verified |
| Sector | Education | Verified |
| Sector | Transportation | Verified |
| Region | South Korea | Verified |
| Region | Middle East Countries | Verified |
Extracted IOCs
- timetrakr[.]cloud
- svc.wompworthy[.]com
- 0c9b911935a3705b0ad569446804d80026feb6db3884aeb240b6c76e9b8cf139
- 128b58a2a2f1df66c474094aacb7e50189025fbf45d7cd8e0834e93a8fbed667
- 3ee7dab4ae4f6d4f16dfabb6f38faef370411a9fc00ff035844e54703b99600a
- 74ab3838ebed7054b2254bf7d334c80c8b2cfec4a97d1706723f8ea55f11061f
- b21c802775df0c0d82c8cfde299084abc624898b10258db641b820172a0ba29a
- bee79c3302b1a7afc0952842d14eff83a604ef00bfdae525176c16c80b2045f7
- c6182fd01b14d84723e3c9d11bc0e16b34de6607ccb8334fc9bb97c1b44f0cde
- d587959841a763669279ad831b8f0379f6a7b037dffc19deab5d41f37f8b5ffc
- e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b
- 104[.]21.48.205
- 172[.]67.156.47
- 178[.]128.233.36
- 179[.]43.177.220
- 34[.]117.59.81
- 37[.]187.78.41
- hxxp://179[.]43.177.220:8080/a[.]dat
- hxxp://179[.]43.177.220:8080/a[.]exe
- hxxp://179[.]43.177.220:8080/nm[.]ps1
- hxxps://svc.wompworthy[.]com
Tip: 21 related IOCs (6 IP, 2 domain, 4 URL, 0 email, 9 file hash) to this threat have been found.
Overlaps
Source: Hunt.io - March 2026
Detection (one case): e25892603c42e34bd7ba0d8ea73be600d898cadc290e3417a82c04d6281b743b
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Seedworm Global Espionage Campaign FAQ
In early 2026, a highly disciplined espionage group successfully breached multiple organizations worldwide, including a major South Korean electronics manufacturer. The attackers maintained undetected access inside networks for extended periods to quietly gather intelligence and steal sensitive information.
The attacks were carried out by a well-known cyber espionage group called Seedworm, which is also tracked under the name MuddyWater. This threat group is widely believed by intelligence analysts to be linked to the Iranian Ministry of Intelligence and Security.
This was a deliberate intelligence-gathering operation rather than a destructive attack. The primary goal was to conduct espionage by stealing highly valuable information, such as intellectual property, research data, and intelligence on rival governments.
The campaign was widespread and sprawling. Based on current discoveries, it affected at least nine distinct organizations located across nine different countries, spanning four continents.
Yes, the attackers targeted a wide variety of specific sectors, including industrial and electronics manufacturing, education, public-sector bodies, and financial services. They specifically sought out networks that held high-value intelligence or provided downstream access to other businesses and customers.
The hackers used legitimate, trusted software programs (like audio drivers and security tools) to sneak their malicious tools into the systems undetected. Once inside, they used automated scripts to silently take screenshots, steal passwords, and tunnel data out of the network using public file-sharing websites.
These organizations hold material that is highly valuable to foreign intelligence services. This includes proprietary high-tech manufacturing details, sensitive global research, and extensive network accesses that can be used as stepping stones to breach other companies.
Organizations should strictly monitor their networks for the unusual use of common administrative tools and unexpected changes to startup settings. It is also vital to block access to unapproved public file-sharing services and train employees to report suspicious, unexpected password prompts on their computers.
While the overall campaign was global in its reach, the attacks themselves were highly targeted. The attackers specifically selected organizations that aligned with their intelligence requirements and carefully tailored their tools to evade detection inside those specific networks.