Signed Binaries Became MuddyWater's Quiet Entry Point

Trusted Windows software is the part defenders are likely to trust first, and MuddyWater is abusing that trust to hide malicious DLLs inside signed executables. The result is a campaign that can pass reputation checks, then use the legitimate wrapper to run code that steals browser credentials and opens covert access. Broadcom, Symantec, Carbon Black, Huntress, and Group-IB linked the Q1 2026 activity to at least nine organizations in nine countries across manufacturing, education, public-sector, financial services, and professional services. The attackers leaned on signed Fortemedia fmapp.exe and SentinelOne sentinelmemoryscanner.exe, and also used Chromium credential theft, screenshot capture, SAM theft, SOCKS5 tunneling, and public file-transfer staging to move data out. The pattern matters because the compromise is built on reuse: the same signed-binary trick, credential theft, and public-hosting staging can be applied across sectors and countries without changing the core playbook. That makes reputation-based filtering and outbound-detection assumptions weak when the malware is riding inside software the system already trusts.

Part of the PlainSec briefing for 2026-05-26

Sources