MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

In what has been called a “false flag” operation, a ransomware attack has been linked to the Iranian state-sponsored hacker outfit MuddyWater (also known as Mango Sandstorm, Seedworm, and Static Kitten).

It has been discovered that the attack, which Rapid7 discovered in early 2026, uses Microsoft Teams and social engineering techniques to start the infection sequence. Evidence suggests that the outbreak is a targeted state-backed operation that poses as opportunistic extortion, despite the first appearance of the incident being compatible with a ransomware-as-a-service (RaaS) group operating under the Chaos brand.

According to Rapid7’s research provided with The Hacker News, the campaign was marked by a high-touch social engineering phase carried out via Microsoft Teams, where the attackers used interactive screen-sharing to collect credentials and manipulate multi-factor authentication (MFA).

Once inside, the gang eschewed file encryption in favor of data exfiltration and long-term persistence via remote management tools like DWAgent read more about MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *