logo

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

ID: 973f425a-0c17-5e8f-8980-c668476dd8a6

STIX ID: report--973f425a-0c17-5e8f-8980-c668476dd8a6

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Rapid7 and other vendors observed a targeted 2026 intrusion attributed to Iranian-linked MuddyWater that leveraged Microsoft Teams social-engineering (interactive screen-sharing), credential harvesting and MFA manipulation to deploy a multi-stage malware chain (ms_upd.exe -> game.exe/Darkcomp RAT, WebView2Loader.dll, encrypted config) and establish long-term persistence via remote management tools (DWAgent, AnyDesk). The operation appears designed as a false-flag: the actors used Chaos ransomware artifacts and off-the-shelf criminal tooling to obscure state sponsorship while prioritizing data exfiltration over file encryption; observed IOCs include an external server (172.86.126.208) and a reused code-signing certificate attributed to "Donald Gay."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.