logo

Hackers Use Microsoft Teams to Steal Credentials and Manipulate MFA

ID: 9000b8d3-dfd4-597a-bd4d-5c4128112b4e

STIX ID: report--9000b8d3-dfd4-597a-bd4d-5c4128112b4e

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Guru Baran

...
...

Rapid7 investigators attribute a 2026 campaign to Iranian APT MuddyWater that masqueraded as Chaos ransomware to distract responders while conducting targeted espionage against U.S. and MENA organizations. Attackers used unsolicited Microsoft Teams external chats and screen-sharing to harvest MFA-protected credentials, instructed victims to save credentials to local files, added attacker devices to MFA, and then deployed DWAgent/AnyDesk and a custom WebView2‑trojanized RAT (Game.exe) for persistence and exfiltration; notable IOCs include IP 172.86.126.208:443, domains moonzonet.com and uploadfiler.com, and a Microsoft code-signing certificate thumbprint B674578D4BDB24CD58BF2DC884EAA658B7AA250C.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.