logo

Iran cybersnoops still LARPing as ransomware crooks in espionage ops

ID: 03582baa-8df6-5fc6-b390-28dfd3919a1d

STIX ID: report--03582baa-8df6-5fc6-b390-28dfd3919a1d

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

...
...

Rapid7 researchers observed activity attributed with medium confidence to the Iran-linked MuddyWater group that impersonated the Chaos ransomware gang to conceal espionage operations: attackers used Microsoft Teams phishing and social engineering to harvest credentials and modify MFA settings, deployed a Darkcomp backdoor and a malicious WebView2 loader via RDP-delivered payloads, moved laterally to collect sensitive data, and published the stolen data on a Chaos data leak site without performing file encryption or seeking a ransom — indicating a false-flag cyberespionage operation and possible prepositioning for destructive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.