logo

Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage

ID: 4cc185de-f307-538b-ab5a-fcd151b061b3

STIX ID: report--4cc185de-f307-538b-ab5a-fcd151b061b3

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-05-07

Date Updated: 2026-05-13

...
...

An Iranian state-linked APT, MuddyWater, carried out a targeted espionage operation in early 2026 that impersonated the Chaos ransomware group to mask data exfiltration. Attackers used social engineering over Microsoft Teams to steal credentials and bypass MFA, deployed remote access tools (DWAgent, AnyDesk) for persistence, and left technical artifacts (including a unique code-signing certificate) that tied the campaign to MuddyWater — demonstrating a trend of nation-state actors adopting criminal tradecraft to frustrate attribution and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.