MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading techniques, leveraging legitimate security software like Fortemedia and SentinelOne to deploy malicious code and steal sensitive data, including passwords and payment card information. This operation highlights a significant escalation in MuddyWater's operational hygiene and involves techniques like Node.js scripts for reconnaissance and data exfiltration via public file-transfer services.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
