MuddyWater Behind Chaos Ransomware: Iranian Espionage Masquerading as Ransomware via Microsoft Teams
Source report →This intrusion set operates under the Chaos ransomware-as-a-service brand and displays the outward indicators of an extortion operation, including data-leak-site branding and ransom demands. Its observed behavior differs from a typical ransomware incident in that the operators do not encrypt files, and instead conduct credential theft, hands-on lateral movement, and the establishment of durable remote access. This pattern is consistent with a data-theft and access-retention operation that uses ransomware branding as cover. Observed targeting spans organizations in the United States, Israel, and the wider Middle East, across the construction, manufacturing, and business services sectors. Infrastructure and tradecraft overlap, with moderate confidence, with Iranian state-aligned espionage activity tracked as MuddyWater.
Initial access is obtained through social engineering over Microsoft Teams. Operators send external chat requests while impersonating internal IT or help-desk personnel, then move targets into interactive screen-sharing sessions. During these sessions the operators harvest credentials, direct users to enter credentials into locally created text files, and modify multi-factor authentication by registering attacker-controlled devices. Using the harvested credentials, the operators authenticate to internal systems and remote-access gateways and establish persistence with legitimate remote-management software, primarily DWAgent and AnyDesk, installed as services and staged in non-standard directories to resemble legitimate software.
Alongside the legitimate tooling, the operators deploy custom malware. A lightweight downloader tracked as Stagecomp, retrieved from attacker infrastructure, delivers a custom remote access trojan tracked as Darkcomp that impersonates a Microsoft WebView2 application, built from a trojanized sample project and signed with a revoked code-signing certificate. The implant employs multiple defense-evasion measures, including runtime resolution of its capabilities, sandbox and virtualization checks prior to execution, and an encrypted configuration file. The operators execute sequences of native discovery commands, move laterally using remote desktop and virtual private network access with the compromised accounts, and communicate with command-and-control infrastructure over HTTPS at a fixed polling interval, exfiltrating collected data over the same channel. No file-encryption payload has been observed across these intrusions, consistent with objectives of data theft and persistent access rather than service disruption.
IOCs (25)
Scan your environment for IOCs →SHA256 FILE HASH 6
24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc01319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b63df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90c86ab27100f2a2939ac0d4a8af511f0a1a8116ba856100aae03bc2ad6cb0f1e0cf3dfd1d6626fd2129abb7a5983c11827f4b0d497e2dba146a1889bd71f23cd5IP ADDRESS 5
77.110.107.23593.123.39.127172.86.126.208116.203.208.186172.86.76.127DOMAIN 8
adm-pulse.commoonzonet.comuploadfiler.comserialmenot.comuppdatefile.comhptqq2o2qjva7lcaaq67w36jihzivkaitkexorauw7b2yul2z6zozpqd.oniongitempire.s3.us-east-005.backblazeb2.comelvenforest.s3.us-east-005.backblazeb2.comURL 1
http://172.86.126.208:443/ms_upd.exeFILE NAME 5
ms_upd.exeDIDS.exeGame.exeWebView2.exevisualwincomp.txtDetections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Credential Named Text File Created On Windows Endpoint
- Multiple Native Discovery Commands Executed on Same Device in a Short Timeframe
- Non Browser Process Beaconing to External Host at a Regular Interval
- Silently Installed RMM via Command Line Interpreter
- Microsoft Teams Chat Initiator Presenting IT Helpdesk Themed Identity
- Authentication From a New Device or Location Shortly After External Teams Contact
- Single Device Establishing Outbound RDP Sessions to Multiple Internal Hosts
- Windows Service Installed From a Newly Created ProgramData Subfolder
- Interpreter Process Injecting Code Into a Suspended Process