Iranian government hackers using Chaos ransomware as cover, researchers say
ID: e1eb2d75-7986-548e-b0c2-fc63c0434b36
STIX ID: report--e1eb2d75-7986-548e-b0c2-fc63c0434b36
Feed Name: The Record from Recorded Future News
Rapid7 researchers link an intrusion that appeared as a Chaos ransomware incident to Iran-aligned APT MuddyWater (MOIS), concluding the ransomware branding was used as a false flag for espionage and data theft; attackers gained access through Microsoft Teams social engineering, harvested VPN credentials via screen-sharing, deployed remote management tools, exfiltrated data and later published stolen files, while lacking file-encryption and showing infrastructure/artifacts tied to prior MuddyWater campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
