Signed Security Binaries Became Seedworm’s Stealth Path

Seedworm turned trusted signed software into the delivery path, so the usual assumption that vendor or security binaries are safe does not hold here. A legitimate executable spawning a malicious DLL and follow-on PowerShell can look like normal software activity, which makes hash-only and unsigned-binary rules easy to miss. Symantec tied the campaign to Iran-linked Seedworm and said it hit at least nine organizations across four continents in early 2026. The targets spanned manufacturing, government, airports, financial services, education, and professional services, using signed Fortemedia and SentinelOne binaries plus a node.exe-based implant chain. The risk persists because the abuse is built around trust, not obvious malware delivery. Even when the initial payload is blocked or removed, the intrusion path can blend into normal endpoint and admin software behavior across a broad set of sectors.

Part of the PlainSec briefing for 2026-05-14

Sources