HomeSecurityMuddyWater uses Chaos ransomware for "cover"

MuddyWater uses Chaos ransomware for “cover”

The notorious Iranian cyberespionage group MuddyWater  appears to have significantly transformed its operational tactics, now adopting methods reminiscent of Chaos -style ransomware attacks . According to an analysis by cybersecurity firm Rapid7 , the perpetrators relied on sophisticated social engineering techniques via Microsoft Teams to gain initial access to corporate environments and establish a permanent presence on victims’ networks.

MuddyWater ransomware Chaos

Microsoft Teams as the initial entry point

The attack began with seemingly innocent conversations on Microsoft Teams, where attackers pretended to be technical support or internal collaborators. Through these conversations, they were able to convince employees to share their screens or enter credentials into fake forms. In several cases phishing pages that imitated Microsoft tools, such as Quick Assist, while there was also a lack of more “manual” deception methods, such as prompting victims to type passwords into local files.

Credential theft and network access consolidation

After gaining access to accounts, the attackers proceeded to penetrate deeper into the corporate environment. According to Rapid7 , connections were observed to critical internal systems, even domain controllers. Remote administration tools such as AnyDesk , RDP , and DWAgent were used to maintain access , creating a permanent channel of control over the infrastructure.

See also: DAEMON Tools Supply Chain Attack: Government organizations targeted

At the same time, the perpetrators allegedly had manipulated Multi -Factor Authentication (MFA) bypass mechanisms , which demonstrates a high level of technical adaptability and understanding of corporate security systems.

Malware and custom attack tools

In the next stage of the attack, researchers detected the use of a loader named ms_upd.exe, which installed a custom backdoor named Game.exe. The malware was presented as a legitimate Microsoft application (WebView2), increasing the likelihood of successful concealment.

MuddyWater uses Chaos ransomware for "cover"

The malware had anti-analysis and anti-virtual machine capabilities, and supported up to 12 different commands. These included executing PowerShell and CMD commands, moving or deleting files, and maintaining remote access to the target system.

The "transformation" into Chaos ransomware and the element of deception

One of the most interesting elements of the research concerns the connection of the attack to the Chaos, a RaaS (ransomware-as-a-service) operation that emerged in 2025 and is known for dual extortion and social engineering attacks, mainly against organizations in the US.

See also: Malware exploits Microsoft Phone Link to steal SMS OTPs

The incident involved ransomware-related tactics, such as data theft, file extraction, and sending extortion emails, and was also listed on the Chaos leak portal. However, analysts believe the ransomware may have acted more as a front to hide a more targeted cyberespionage operation.

Performance in MuddyWater and geopolitical implications

Rapid7 describes the MuddyWater attack as “medium confidence,” but it is based on strong evidence, including shared infrastructure, technical similarities to previous operations, and specific digital certificates that have been linked to malware such as Stagecomp and Darkcomp .

MuddyWater, also known as Static Kitten, Mango Sandstorm, and Seedworm, is linked to Iranian state-sponsored entities and is believed to operate under the auspices of the Ministry of Intelligence and Security (MOIS). This reinforces the geopolitical dimension of the attack, as it suggests that the targets are not exclusively economic.

MuddyWater uses Chaos ransomware for "cover"

Convergence of cyberespionage and cybercrime

Researchers point to a growing convergence between state-sponsored groups and criminal ransomware ecosystems. The use of tools like Chaos is not necessarily aimed at financial gain, but rather at covering up real espionage operations and making it difficult to attribute responsibility.

See also: Chinese UAT-8302 hackers target governments with custom malware

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This case shows that the boundaries between cyberespionage and cybercrime are becoming increasingly blurred, creating a new, hybrid threat landscape.

Implications for cybersecurity and the future of threats

This development highlights the need for enhanced protection for collaboration tools like Microsoft Teams, which are now a prime target for social engineering attacks. At the same time, it highlights the importance of multi-layered defense, user education, and continuous monitoring of network activity.

In an environment where state and criminal networks collaborate or imitate each other, distinguishing between real ransomware and espionage operations is becoming increasingly difficult, making cybersecurity more critical than ever.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS