CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

MuddyWater

actor · actor:muddywater single-source

Iran MOIS-linked APT active against European and Middle-Eastern targets; 2026 pipeline coverage documents a Chaos-ransomware false-flag with Teams credential harvesting and a Q1 2026 DLL side-loading campaign abusing signed Fortemedia/SentinelOne binaries with ChromElevator ABE bypass (Symantec).

Aliases: Seedworm

Coverage
4
2 about it · 2 mentions · first 2026-05-08 → last 2026-09-21
Latest activity
2026-05-28
MuddyWater / Seedworm, Symantec and Carbon Black document new DLL-side-loading pair via signed Fortemedia and…
Peak priority
notable
2 notable
Targets
education
sectors: education, public-sector, manufacturing · regions: middle-east, europe, apac
Sources cited
6
6 hosts
2026-05-084 appearances2026-09-21

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

overlaps with

attributed activity

Story timeline

Every entry that names MuddyWater, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.

  1. 2026-09-21REF9334/KREMLIN forges Chromium's own Secure Preferences integrity hashes to silently install a banking-fraud browser extension outside the Web Store, resolving C2 through an Ethereum smart contract
    mentionactive-threatsElastic Security Labs: a Brazilian banking-fraud toolkit defeats Chromium's extension-integrity check by extracting the browser's own signing keys from memory
  2. 2026-07-09Check Point: Iran MOIS-linked "Cavern Manticore" ships a modular .NET C2 that uses three compilation formats as an anti-analysis layer, delivered via SysAid RMM abuse
    mentionactive-threatsCavern Manticore's C2 splits across IL, Mixed-Mode and NativeAOT binaries to break RE toolchains, pushed through SysAid's legitimate deployment feature
  3. 2026-05-28MuddyWater / Seedworm, Symantec and Carbon Black document new DLL-side-loading pair via signed Fortemedia and SentinelOne binaries, ChromElevator for Chromium App-Bound Encryption bypass, Node.js orchestration
    researchMuddyWater / Seedworm, Symantec and Carbon Black document new DLL-side-loading pair via signed Fortemedia and SentinelOne binaries, ChromElevator for Chromium
  4. 2026-05-08MuddyWater (Iran/MOIS) deploys Chaos ransomware as false flag; harvests credentials via Teams
    active-threats
ATT&CK techniques (7 across 5 tactics)

7 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessPhishing: Spearphishing Voice
  • Credential AccessOS Credential Dumping: Security Account Manager · Steal or Forge Authentication Certificates
  • DiscoveryAccount Discovery · Domain Trust Discovery
  • Command and ControlProxy: Multi-hop Proxy
  • ImpactData Encrypted for Impact

Initial Access TA0001

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-05-08/muddywater-iran-mois-deploys-chaos-ransomware-as-false-flag · ATT&CK page ↗

Credential Access TA0006

T1003.002OS Credential Dumping: Security Account Manager×1

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.

Evidence: 2026-05-28/muddywater-seedworm-symantec-and-carbon-black-document-new-d · ATT&CK page ↗

T1649Steal or Forge Authentication Certificates×1

Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files. Certificates are also used as authentication material. For example, Entra ID device certificates and Active Directory Certificate Services (AD CS) certificates bind to an identity and can be used as credentials for domain accounts.

Evidence: 2026-05-08/muddywater-iran-mois-deploys-chaos-ransomware-as-false-flag · ATT&CK page ↗

Discovery TA0007

T1087Account Discovery×1

Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts).

Evidence: 2026-05-28/muddywater-seedworm-symantec-and-carbon-black-document-new-d · ATT&CK page ↗

T1482Domain Trust Discovery×1

Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.

Evidence: 2026-05-28/muddywater-seedworm-symantec-and-carbon-black-document-new-d · ATT&CK page ↗

Command and Control TA0011

T1090.003Proxy: Multi-hop Proxy×1

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-05-28/muddywater-seedworm-symantec-and-carbon-black-document-new-d · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-05-08/muddywater-iran-mois-deploys-chaos-ransomware-as-false-flag · ATT&CK page ↗

Entries about MuddyWater (2)

2026-05-28 · view entry permalink →

NOTABLE

MuddyWater / Seedworm, Symantec and Carbon Black document new DLL-side-loading pair via signed Fortemedia and SentinelOne binaries, ChromElevator for Chromium App-Bound Encryption bypass, Node.js orchestration

Symantec's Threat Hunter Team and Broadcom's Carbon Black published findings on 2026-05-12 documenting a Q1 2026 MuddyWater (a.k.a. Seedworm, Static Kitten, MERCURY, TEMP.Zagros, attributed to Iran's Ministry of Intelligence and Security) espionage campaign across at least nine organisations on four continents. The story re-surfaced this run via fresh aggregator coverage on 2026-05-26 (The Hacker News), included in window on that basis. Named victim categories include industrial and electronics manufacturing, education and public-sector bodies, financial services, and an international airport in the Middle East (Symantec / Broadcom Threat Intelligence, 2026-05-12; The Hacker News, 2026-05-26; Industrial Cyber, 2026-05-13).

The differentiating TTPs from prior MuddyWater coverage are twofold. First, DLL side-loading via two pairs of legitimately signed third-party binaries: Fortemedia audio-driver binary fmapp.exe side-loading a malicious fmapp.dll; SentinelOne's sentinelmemoryscanner.exe side-loading a rogue sentinelagentcore.dll, abuse of a signed security-product binary specifically chosen to bypass signature-based detection. Both malicious DLLs embed ChromElevator, an open-source post-exploitation tool that bypasses Chromium App-Bound Encryption to extract passwords, cookies and payment-card data without triggering AV. Second, orchestration moved to Node.js: node.exe appears as a parent-process ancestor of cmd.exe before any operator commands, i.e. a Node.js script (not a human operator) drives the kill chain. PowerShell scripts pulled from a staging server perform discovery (T1087, T1482), screenshot capture, SAM-hive theft via VSS (T1003.002), and SOCKS5 reverse-proxy tunnelling (T1090.003). A credential harvester calls CredUIPromptForWindowsCredentialsW to display a Windows security dialogue and trick targets into entering credentials. A Kerberos TGT extractor via GSS-API was also observed.

Why it matters to us: signed-binary side-loading abusing a security-product binary is the highest-value evasion class; signature-based controls are bypassed by design. Detection: Sysmon EID 7 image-loads from fmapp.exe or sentinelmemoryscanner.exe outside their expected installation directories; alert on node.exe as a parent of cmd.exe or powershell.exe -enc in non-developer environments; flag CredUIPromptForWindowsCredentialsW calls from non-standard parents. Hardening: AppLocker / WDAC enforcing signed-and-known-path DLL loads; restrict node.exe execution to development OUs.

research28 May 05:00Zmulti-sourceOpen finding →

2026-05-08 · view entry permalink →

NOTABLE

MuddyWater (Iran/MOIS) deploys Chaos ransomware as false flag; harvests credentials via Teams

Security researchers documented a refreshed campaign by MuddyWater (attributed to Iran's Ministry of Intelligence and Security, MOIS), targeting government contractors and defence-adjacent organisations in Europe and the Middle East. The campaign deploys Chaos ransomware payloads with branding designed to mimic criminal ransomware groups, a deliberate false-flag technique intended to complicate attribution and delay incident response triage. A parallel social-engineering vector uses Microsoft Teams external-access invitations to gain remote-assistance sessions under a helpdesk pretext, after which credentials are harvested and used for further access via legitimate cloud services. Observed ATT&CK techniques: T1566.004 (Spearphishing via Teams), T1649 (Steal or Forge Authentication Certificates), T1486 (Data Encrypted for Impact). This is a single-source threat-intelligence vendor disclosure.

threat08 May 05:00Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats3
  • Research1

Source distribution

  • deepinstinct.com1 (17%)
  • elastic.co1 (17%)
  • industrialcyber.co1 (17%)
  • research.checkpoint.com1 (17%)
  • security.com1 (17%)
  • thehackernews.com1 (17%)