MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
ID: 973f425a-0c17-5e8f-8980-c668476dd8a6
STIX ID: report--973f425a-0c17-5e8f-8980-c668476dd8a6
Feed Name: The Hacker News
Rapid7 and other vendors observed a targeted 2026 intrusion attributed to Iranian-linked MuddyWater that leveraged Microsoft Teams social-engineering (interactive screen-sharing), credential harvesting and MFA manipulation to deploy a multi-stage malware chain (ms_upd.exe -> game.exe/Darkcomp RAT, WebView2Loader.dll, encrypted config) and establish long-term persistence via remote management tools (DWAgent, AnyDesk). The operation appears designed as a false-flag: the actors used Chaos ransomware artifacts and off-the-shelf criminal tooling to obscure state sponsorship while prioritizing data exfiltration over file encryption; observed IOCs include an external server (172.86.126.208) and a reused code-signing certificate attributed to "Donald Gay."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
