Hackers Use Microsoft Teams to Steal Credentials and Manipulate MFA
ID: 9000b8d3-dfd4-597a-bd4d-5c4128112b4e
STIX ID: report--9000b8d3-dfd4-597a-bd4d-5c4128112b4e
Feed Name: cybersecurityNews.com
Rapid7 investigators attribute a 2026 campaign to Iranian APT MuddyWater that masqueraded as Chaos ransomware to distract responders while conducting targeted espionage against U.S. and MENA organizations. Attackers used unsolicited Microsoft Teams external chats and screen-sharing to harvest MFA-protected credentials, instructed victims to save credentials to local files, added attacker devices to MFA, and then deployed DWAgent/AnyDesk and a custom WebView2‑trojanized RAT (Game.exe) for persistence and exfiltration; notable IOCs include IP 172.86.126.208:443, domains moonzonet.com and uploadfiler.com, and a Microsoft code-signing certificate thumbprint B674578D4BDB24CD58BF2DC884EAA658B7AA250C.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
