Iranian APT MuddyWater Masquerades as Chaos Ransomware in Elaborate False Flag
ID: 6cb5284f-7d35-5e3f-b9de-f0ffcfa6510b
STIX ID: report--6cb5284f-7d35-5e3f-b9de-f0ffcfa6510b
Feed Name: securityonline.info
Rapid7 investigators determined an intrusion masquerading as Chaos ransomware was in fact a MuddyWater (Seedworm) operation: attackers used Microsoft Teams screen-sharing and social engineering to harvest credentials and bypass MFA, deployed a custom RAT ('Game.exe') and DWAgent for persistence, exfiltrated data rather than encrypting files, and staged ransomware-themed extortion to obfuscate attribution; forensic ties include a known MuddyWater code-signing certificate issued to "Donald Gay" and overlapping C2 infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
