news.mlab.sh
Back to the feed
threat-intel

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

High
Image: The Hacker News
Summary

The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading techniques, leveraging legitimate security software like Fortemedia and SentinelOne to deploy malicious code and steal sensitive data, including passwords and payment card information. This operation highlights a significant escalation in MuddyWater's operational hygiene and involves techniques like Node.js scripts for reconnaissance and data exfiltration via public file-transfer services.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.