Threats Feed|MuddyWater|Last Updated 13/05/2026|AuthorCertfa Radar|Publish Date06/05/2026

False Flag Cyber Espionage: How Iranian Actors Weaponized the Chaos RaaS Brand

  • Actor Motivations: Espionage,Exfiltration,Extortion
  • Attack Vectors: Compromised Credentials,Downloader,Ransomware,RAT,Trojan,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

In early 2026, the Iranian state-sponsored APT MuddyWater executed a sophisticated false-flag operation masquerading as a Chaos ransomware attack. Primarily targeting the United States, Israel, and MENA organizations—specifically within the construction, manufacturing, and business services sectors—the group bypassed traditional encryption. Instead, they focused on data exfiltration and long-term espionage. Initial access was achieved via Microsoft Teams social engineering, enabling interactive credential harvesting and MFA manipulation. Attackers established persistence using legitimate remote access tools like DWAgent alongside a custom trojanized WebView2 RAT. Analysis of C2 infrastructure and an MOIS-linked code-signing certificate confirmed the attribution. This hybrid intrusion highlights how state actors increasingly leverage cybercriminal RaaS branding to obscure intelligence-gathering operations.

Detected Targets

TypeDescriptionConfidence
RegionIsrael
High
RegionUnited States
High

Extracted IOCs

  • adm-pulse[.]com
  • moonzonet[.]com
  • uploadfiler[.]com
  • 1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6
  • 24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14
  • 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90
  • 86e0197389f0573eb83ff53991f337d416124c7c8bd727721ef3d396cd5f65dc
  • a3bac548b5bc91c526b4d6707623ddbd1a675aa952f0d1f9a0aa6f7230f09f23
  • a47cd0dc12f0152d8f05b79e5c86bac9231f621db7b0e90a32f87b98b4e82f3a
  • a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
  • bfc1675ee1e358db8356f515aaded7962923e426aa0a0a1c0eddfc4dab053f89
  • c86ab27100f2a2939ac0d4a8af511f0a1a8116ba856100aae03bc2ad6cb0f1e0
  • cd098eddb23f2d2f6c42271ca82803b0d5ac950cb82a9b8ae0928e83945a53df
  • cf3dfd1d6626fd2129abb7a5983c11827f4b0d497e2dba146a1889bd71f23cd5
  • 116[.]203.208.186
  • 172[.]86.126.208
  • 77[.]110.107.235
  • 93[.]123.39.127
download

Tip: 18 related IOCs (4 IP, 3 domain, 0 URL, 0 email, 11 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater Adopts Russian CastleRAT MaaS for Upgraded Cyber Espionage

Source: JUMPSEC - April 2026

Detection (two cases): 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0

Void ManticoreIranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations

Source: Check Point - March 2026

Detection (two cases): 24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0

SeedwormIranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors

Source: Symantec - March 2026

Detection (five cases): 1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6, 24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14, 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90, a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0, moonzonet[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

The MuddyWater "Chaos" Deception

An organization experienced a severe network intrusion that initially looked like a standard extortion attempt by the Chaos ransomware group. However, deep forensic analysis revealed that the attack was actually a "false flag" operation, meaning the attackers faked a ransomware incident to cover up a highly sophisticated cyber espionage mission.

Evidence strongly indicates the attack was carried out by MuddyWater (also known as Seedworm), a state-sponsored Advanced Persistent Threat (APT) group. MuddyWater is formally affiliated with Iran's Ministry of Intelligence and Security (MOIS) and is well-known for conducting geopolitical intelligence gathering.

Unlike typical ransomware gangs that want to lock your files and demand money, this group's primary goal was long-term data theft and network infiltration. They completely skipped encrypting the victim's files, using the ransomware extortion emails and leak sites merely as a disguise to confuse defenders and hide their true espionage objectives.

While the Chaos ransomware brand typically targets organizations in the United States (especially in construction, manufacturing, and business services), MuddyWater's broader cyber espionage operations span much further. Their recent campaigns have actively targeted organizations across the U.S., Israel, and the Middle East and North Africa (MENA) regions.

The attackers specifically targeted internal employees, using interactive chats to trick them into handing over access. The ultimate target was the organization's sensitive internal data and network infrastructure, which state-sponsored actors seek out for strategic advantage or to preposition themselves for future attacks.

The attackers started by messaging employees on Microsoft Teams, pretending to be IT support to get the victims to share their screens. Once connected, they convinced the employees to type out their passwords and change their security settings, which allowed the attackers to quietly install remote-control software and custom malware to steal data.

Organizations targeted by state-sponsored intelligence groups possess valuable geopolitical, strategic, or proprietary data. Compromising these networks not only provides attackers with immediate intelligence but also allows them to establish a hidden foothold inside the network for future disruptions.

Organizations should restrict or closely monitor external messages coming into enterprise chat apps like Microsoft Teams and block unapproved remote desktop software. Employees must remain highly vigilant against anyone asking to share screens or type out passwords, even if the person claims to be internal IT support.

This specific incident was a highly targeted cyber espionage intrusion. However, the overarching tactic—state-sponsored spies hiding their tracks by pretending to be common cybercriminals, is becoming a widespread and increasingly common strategy in global cyber warfare.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights