HIGH: Iranian MuddyWater APT Hits Nine Countries With Signed-Binary DLL Side-Loading Through SentinelOne and Fortemedia
Symantec and Carbon Black detail a Q1 2026 MuddyWater espionage campaign that breached nine organisations across nine countries on four continents, abusing signed SentinelOne and Fortemedia binaries for DLL side-loading and deploying ChromElevator, a Node.js implant, and the FileFiend exfiltration tool. The Iranian MOIS-linked group is moving toward quieter, more disciplined operations.