Iran cybersnoops still LARPing as ransomware crooks in espionage ops
ID: 03582baa-8df6-5fc6-b390-28dfd3919a1d
STIX ID: report--03582baa-8df6-5fc6-b390-28dfd3919a1d
Feed Name: The Register (Security)
Rapid7 researchers observed activity attributed with medium confidence to the Iran-linked MuddyWater group that impersonated the Chaos ransomware gang to conceal espionage operations: attackers used Microsoft Teams phishing and social engineering to harvest credentials and modify MFA settings, deployed a Darkcomp backdoor and a malicious WebView2 loader via RDP-delivered payloads, moved laterally to collect sensitive data, and published the stolen data on a Chaos data leak site without performing file encryption or seeking a ransom — indicating a false-flag cyberespionage operation and possible prepositioning for destructive actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
