logo

Iranian APT MuddyWater Masquerades as Chaos Ransomware in Elaborate False Flag

ID: 6cb5284f-7d35-5e3f-b9de-f0ffcfa6510b

STIX ID: report--6cb5284f-7d35-5e3f-b9de-f0ffcfa6510b

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ddos

...
...

Rapid7 investigators determined an intrusion masquerading as Chaos ransomware was in fact a MuddyWater (Seedworm) operation: attackers used Microsoft Teams screen-sharing and social engineering to harvest credentials and bypass MFA, deployed a custom RAT ('Game.exe') and DWAgent for persistence, exfiltrated data rather than encrypting files, and staged ransomware-themed extortion to obfuscate attribution; forensic ties include a known MuddyWater code-signing certificate issued to "Donald Gay" and overlapping C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.