Iran MOIS-Linked MuddyWater Deploys False Flag Ransomware Posing as Chaos Group
In early 2026, Rapid7 investigated an intrusion in which actors used Microsoft Teams screen-sharing sessions to harvest credentials and manipulate MFA, then established persistence through DWAgent and AnyDesk. The attackers moved laterally via RDP, exfiltrated data, and deployed a custom RAT (Game.exe, dubbed Darkcomp) masquerading as a legitimate Microsoft WebView2 application. No file-encrypting ransomware ran on victim machines despite Chaos ransomware artifacts and the victim's appearance on the Chaos data leak site, from which stolen data was later published. Rapid7 attributed the activity to MuddyWater at moderate confidence, citing a code-signing certificate previously used by the group and C2 domains consistent with prior MuddyWater operations.
MuddyWater's use of the Chaos ransomware brand as cover for what was operationally a data theft and espionage mission marks a deliberate expansion of Iranian false-flag doctrine beyond simple infrastructure borrowing. The group extracted data and arranged its publication on a criminal leak site while never executing file encryption, demonstrating the ransomware persona served denial-and-deception rather than a revenue objective. The Microsoft Teams social engineering vector used to harvest credentials and manipulate MFA signals adaptation to enterprise collaboration tools as a preferred initial access path, reducing reliance on commodity phishing. We assess it
4 sources
- MuddyWater Uses Microsoft Teams to Deploy False Flag Ransomware -
The Hacker News - Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware -
Rapid7 - MuddyWater hackers use Chaos ransomware as a decoy in attacks -
BleepingComputer - Iranian APT Intrusion Masquerades as Chaos Ransomware Attack -
SecurityWeek