Minacce · 140 giorni fa
Seedworm ha trasformato software firmato e affidabile nel percorso di consegna, quindi la consueta assunzione che i vendor o i security binaries siano sicuri qui non vale. Un eseguibile legittimo che avvia una DLL malevola e una PowerShell successiva può sembrare normale attività software, il che rende facili da mancare le regole basate solo su hash e sui unsigned-binary.
2 fonti che coprono questa storia
Iranian hackers targeted major South Korean electronics maker
The Iran-linked hacking group MuddyWater (a.k.a.
Symantec uncovers Iran-linked Seedworm espionage campaign targeting airport, government, manufacturing sectors
Part of the PlainSec briefing for 2026-05-14