MuddyWater hackers use Chaos ransomware as a decoy in attacks
ID: 5307d5dd-f197-5aaf-9dc0-867ef38c47b0
STIX ID: report--5307d5dd-f197-5aaf-9dc0-867ef38c47b0
Feed Name: Bleeping Computer
Rapid7 observed MuddyWater (an Iranian state-sponsored APT) conducting a cyber-espionage operation that used Chaos ransomware as a decoy: attackers lured victims via Microsoft Teams social engineering, harvested credentials, manipulated MFA, deployed remote-access tools (AnyDesk, RDP), established persistence, and installed a custom backdoor (Game.exe) via a loader (ms_upd.exe) to enable command execution, exfiltration, and extortion; attribution to MuddyWater is based on infrastructure overlap, a shared code-signing certificate, and operational tradecraft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
