logo

Iranian cyber espionage disguised as a Chaos Ransomware attack

ID: 25c1fa28-2e44-5160-855e-d0f6f8fb1187

STIX ID: report--25c1fa28-2e44-5160-855e-d0f6f8fb1187

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Pierluigi Paganini

...
...

Rapid7 uncovered a 2026 campaign where the Iran-linked APT MuddyWater masqueraded as the Chaos ransomware group to conceal espionage: attackers used Microsoft Teams social engineering to obtain screen sharing and credentials, deployed remote access tools (AnyDesk, DWAgent), installed backdoors (Dindoor, Fakeset), exfiltrated data (Rclone to cloud storage), and staged extortion/ leak site activity as a false flag, with artifacts (code-signing certificates, C2 infrastructure) supporting moderate-confidence attribution to MuddyWater.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.