Iranian cyber espionage disguised as a Chaos Ransomware attack
ID: 25c1fa28-2e44-5160-855e-d0f6f8fb1187
STIX ID: report--25c1fa28-2e44-5160-855e-d0f6f8fb1187
Feed Name: Security Affairs
Rapid7 uncovered a 2026 campaign where the Iran-linked APT MuddyWater masqueraded as the Chaos ransomware group to conceal espionage: attackers used Microsoft Teams social engineering to obtain screen sharing and credentials, deployed remote access tools (AnyDesk, DWAgent), installed backdoors (Dindoor, Fakeset), exfiltrated data (Rclone to cloud storage), and staged extortion/ leak site activity as a false flag, with artifacts (code-signing certificates, C2 infrastructure) supporting moderate-confidence attribution to MuddyWater.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
