The notorious Iranian cyberespionage group MuddyWater appears to have significantly transformed its operational tactics, now adopting methods reminiscent of Chaos -style ransomware attacks . According to an analysis by cybersecurity firm Rapid7 , the perpetrators relied on sophisticated social engineering techniques via Microsoft Teams to gain initial access to corporate environments and establish a permanent presence on victims’ networks.

Microsoft Teams as the initial entry point
The attack began with seemingly innocent conversations on Microsoft Teams, where attackers pretended to be technical support or internal collaborators. Through these conversations, they were able to convince employees to share their screens or enter credentials into fake forms. In several cases phishing pages that imitated Microsoft tools, such as Quick Assist, while there was also a lack of more “manual” deception methods, such as prompting victims to type passwords into local files.
Credential theft and network access consolidation
After gaining access to accounts, the attackers proceeded to penetrate deeper into the corporate environment. According to Rapid7 , connections were observed to critical internal systems, even domain controllers. Remote administration tools such as AnyDesk , RDP , and DWAgent were used to maintain access , creating a permanent channel of control over the infrastructure.
See also: DAEMON Tools Supply Chain Attack: Government organizations targeted
At the same time, the perpetrators allegedly had manipulated Multi -Factor Authentication (MFA) bypass mechanisms , which demonstrates a high level of technical adaptability and understanding of corporate security systems.
Malware and custom attack tools
In the next stage of the attack, researchers detected the use of a loader named ms_upd.exe, which installed a custom backdoor named Game.exe. The malware was presented as a legitimate Microsoft application (WebView2), increasing the likelihood of successful concealment.

The malware had anti-analysis and anti-virtual machine capabilities, and supported up to 12 different commands. These included executing PowerShell and CMD commands, moving or deleting files, and maintaining remote access to the target system.
The "transformation" into Chaos ransomware and the element of deception
One of the most interesting elements of the research concerns the connection of the attack to the Chaos, a RaaS (ransomware-as-a-service) operation that emerged in 2025 and is known for dual extortion and social engineering attacks, mainly against organizations in the US.
See also: Malware exploits Microsoft Phone Link to steal SMS OTPs
The incident involved ransomware-related tactics, such as data theft, file extraction, and sending extortion emails, and was also listed on the Chaos leak portal. However, analysts believe the ransomware may have acted more as a front to hide a more targeted cyberespionage operation.
Performance in MuddyWater and geopolitical implications
Rapid7 describes the MuddyWater attack as “medium confidence,” but it is based on strong evidence, including shared infrastructure, technical similarities to previous operations, and specific digital certificates that have been linked to malware such as Stagecomp and Darkcomp .
MuddyWater, also known as Static Kitten, Mango Sandstorm, and Seedworm, is linked to Iranian state-sponsored entities and is believed to operate under the auspices of the Ministry of Intelligence and Security (MOIS). This reinforces the geopolitical dimension of the attack, as it suggests that the targets are not exclusively economic.

Convergence of cyberespionage and cybercrime
Researchers point to a growing convergence between state-sponsored groups and criminal ransomware ecosystems. The use of tools like Chaos is not necessarily aimed at financial gain, but rather at covering up real espionage operations and making it difficult to attribute responsibility.
See also: Chinese UAT-8302 hackers target governments with custom malware
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This case shows that the boundaries between cyberespionage and cybercrime are becoming increasingly blurred, creating a new, hybrid threat landscape.
Implications for cybersecurity and the future of threats
This development highlights the need for enhanced protection for collaboration tools like Microsoft Teams, which are now a prime target for social engineering attacks. At the same time, it highlights the importance of multi-layered defense, user education, and continuous monitoring of network activity.
In an environment where state and criminal networks collaborate or imitate each other, distinguishing between real ransomware and espionage operations is becoming increasingly difficult, making cybersecurity more critical than ever.
source: www.bleepingcomputer.com
