INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Iran-Linked APT Exploits Chaos Ransomware Tactics

| 2026-05-06 13:00 CRITICAL MEDIUM RANSOMWARE & EXTORTION STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The threat actor behind the recent Chaos ransomware campaign, linked to Iran's Ministry of Intelligence and Security, has been revealed through a new report by security vendor Rapid7. The intrusion began with social engineering via Microsoft Teams screen sharing, followed by an "obfuscation can't hide" approach that used a countdown timer to conceal data exfiltration. This hybrid model leveraged ransomware as a means for plausible deniability and operational flexibility within a broader intelligence-driven campaign.
Technical Mitigations AI-generated
• Implement secure authentication and authorization mechanisms to prevent unauthorized access to systems, such as MFA (Multi-Factor Authentication) for all users. • Regularly update software and operating systems with the latest security patches and updates to fix known vulnerabilities. • Use secure communication protocols, such as encrypted email or messaging apps, when communicating sensitive information. • Monitor system logs and network traffic for suspicious activity, which can help detect potential intrusion attempts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

py•••••.exe
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
MuddyWaterMuddyWater Pay2KeyPay2KeyQilinQilin
Target & Sectors
NORTH_AMERICA NORTH_AMERICA DPRK DPRK governmentgovernment healthhealth
Incident Timeline
‎February 2025
Iranian government hackers used the Chaos ransomware operation.
tactic Ransomware
organisation BlackSuit
‎2025/05/07
Iranian government hackers used the MuddyWater ransomware strain to target an Israeli organization in May 2025.
tactic Ransomware
threat_actor MuddyWater
malware Qilin
target_region Israel
‎late 2025
Iranian government hackers used Chaos Ransomware to target an Israeli organization, Rapid7 reported.
malware Qilin
source_region Israel
‎May 6
Iranian government hackers used Chaos ransomware.
tactic Ransomware
‎2026/05/06
Iranian government hackers used Chaos ransomware to target a US healthcare organization in late February.
organisation Espionage Campaign
threat_actor MuddyWater
organisation DLS
organisation Microsoft
organisation Microsoft Teams
organisation AnyDesk
organisation MFA
organisation TA
organisation DWAgent
‎early 2026
Rapid7 branded an intrusion as a false flag operation by the MuddyWater group affiliated with Iran's Ministry of Intelligence and Security.
threat_actor MuddyWater
attribution Seedworm
attribution the Iranian Ministry of Intelligence and Security
tactic Espionage
Intelligence Sources