logo

Iran-Linked APT Posed as Chaos Ransomware Member in Espionage Campaign

ID: ec52d80a-f1c0-5dc4-a12e-9b89a75b7f02

STIX ID: report--ec52d80a-f1c0-5dc4-a12e-9b89a75b7f02

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

...
...

Rapid7 reports that Iranian-linked APT MuddyWater conducted a false-flag intrusion in early 2026 by impersonating Chaos ransomware affiliates to mask intelligence-driven espionage and prepositioning. The intrusion leveraged interactive Microsoft Teams social engineering to harvest credentials and manipulate MFA, established persistence with remote access tools (DWAgent, AnyDesk), exfiltrated legitimate data, and initiated extortion behaviors without deploying a ransomware payload; investigators found links to prior MuddyWater infrastructure including a code-signing certificate, the moonzonet.com domain, and specific process injection techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.