Hackers Exploit Microsoft Teams to Steal Credentials and Bypass MFA
ID: 83461f2e-9c5d-57c3-9bc4-4914034f820b
STIX ID: report--83461f2e-9c5d-57c3-9bc4-4914034f820b
Feed Name: Cyber Press
Threat Score
Iran-linked MuddyWater conducted a covert espionage campaign in early 2026 that masqueraded as Chaos ransomware activity; attackers used Microsoft Teams social engineering to harvest credentials and add attacker-controlled MFA devices, deployed a downloader (ms_upd.exe) and a custom RAT (Game.exe) that communicated with C2 domains, and used legitimate remote management tools and RDP to maintain persistence while avoiding file encryption to conceal true objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
