INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

MuddyWater uses Chaos ransomware as decoy

| 2026-05-06 13:02 CRITICAL HIGH
Executive Summary AI-generated
The MuddyWater Iranian cyber-espionage group, notorious for long-term network intrusion campaigns targeting organizations in the United States and other countries, has been linked to a ransomware-as-a-service (RaaS) operation known as Chaos. This threat actor's tactics include social engineering, credential theft, persistence, remote access, data exfiltration, extortion emails, and an entry on the Chaos leak portal. MuddyWater is believed to have pivoted from using this RaaS component in a late 2025 attack against an Israeli organization, suggesting that it may be adapting its strategy as attribution efforts intensify.
Technical Mitigations AI-generated
* Implement robust multi-factor authentication (MFA) policies to prevent unauthorized access and reduce the attack surface. * Regularly update and patch software, including Microsoft Teams, to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Use secure communication channels, such as encrypted messaging apps or email services with end-to-end encryption, for sensitive communications. * Conduct regular security audits and vulnerability assessments of systems and networks to identify potential entry points for attackers. * Educate employees on social engineering tactics and phishing attempts, and provide training on how to respond to suspicious emails and messages.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
MuddyWaterMuddyWater PowGoopPowGoopQilinQilin
Target & Sectors
GCC GCC NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎September 2020
MuddyWater hackers used Chaos ransomware as a decoy in attacks targeting prominent Israeli organizations.
tactic Ransomware
target_region Israel
malware PowGoop
‎late 2025
The MOIS operatives deployed Qilin ransomware in an attack against the Israeli organization late in 2025.
tactic Ransomware
malware Qilin
target_region Israel
organisation MOIS
‎early 2025
MuddyWater hackers used Chaos ransomware as a decoy in early 2025 attacks targeting the group.
‎October 2025
The MuddyWater hackers used Qilin ransomware to target an Israeli government hospital in October 2025.
tactic Ransomware
malware Qilin
target_region Israel
‎late March 2026
MuddyWater hackers used Chaos ransomware to target the U.S. Construction sector in late March 2026, claiming 36 victims on its data leak site.
tactic Data Leak
organisation the U.S. Construction
victims 36 victims
‎2026/05/06
MuddyWater hackers used Chaos ransomware as a decoy in their attacks.
threat_actor MuddyWater
organisation Microsoft Teams
organisation DWAgent
organisation Microsoft
organisation DarkBit
organisation Microsoft Quick Assist
organisation Teams
organisation RAMP
organisation RehubCom
organisation MFA
organisation AnyDesk
organisation The Hacker News
organisation Static Kitten
organisation Seedworm
data_breach 26,000 user records
organisation TA
organisation Credential
organisation Next
organisation DLL
organisation U.S. Navy
infrastructure Windows
organisation Microsoft Edge
organisation the Ministry of Justice
organisation Legal Affairs
organisation Ctrl-Alt-Intel
organisation Broadcom, Check Point
organisation JUMPSEC
organisation CastleLoader
organisation Check Point Research
‎early 2026
MuddyWater hackers used Chaos ransomware as a decoy in their attacks, targeting Microsoft Teams.
tactic Social Engineering
organisation Microsoft Teams
‎May 12
MuddyWater hackers used Chaos ransomware as a decoy in the Autonomous Validation Summit.
organisation the Autonomous Validation Summit
general_metric 14 May
Tactical Metrics
Metrics
victims
36
Victims
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
26,000
User Records
Intelligence Sources