logo

Iranian government hackers using Chaos ransomware as cover, researchers say

ID: e1eb2d75-7986-548e-b0c2-fc63c0434b36

STIX ID: report--e1eb2d75-7986-548e-b0c2-fc63c0434b36

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

...
...

Rapid7 researchers link an intrusion that appeared as a Chaos ransomware incident to Iran-aligned APT MuddyWater (MOIS), concluding the ransomware branding was used as a false flag for espionage and data theft; attackers gained access through Microsoft Teams social engineering, harvested VPN credentials via screen-sharing, deployed remote management tools, exfiltrated data and later published stolen files, while lacking file-encryption and showing infrastructure/artifacts tied to prior MuddyWater campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.