← All briefs
high July 22, 2026

MuddyWater Behind Chaos Ransomware: Iranian Espionage Masquerading as Ransomware via Microsoft Teams

Source report →

This intrusion set operates under the Chaos ransomware-as-a-service brand and displays the outward indicators of an extortion operation, including data-leak-site branding and ransom demands. Its observed behavior differs from a typical ransomware incident in that the operators do not encrypt files, and instead conduct credential theft, hands-on lateral movement, and the establishment of durable remote access. This pattern is consistent with a data-theft and access-retention operation that uses ransomware branding as cover. Observed targeting spans organizations in the United States, Israel, and the wider Middle East, across the construction, manufacturing, and business services sectors. Infrastructure and tradecraft overlap, with moderate confidence, with Iranian state-aligned espionage activity tracked as MuddyWater.

Initial access is obtained through social engineering over Microsoft Teams. Operators send external chat requests while impersonating internal IT or help-desk personnel, then move targets into interactive screen-sharing sessions. During these sessions the operators harvest credentials, direct users to enter credentials into locally created text files, and modify multi-factor authentication by registering attacker-controlled devices. Using the harvested credentials, the operators authenticate to internal systems and remote-access gateways and establish persistence with legitimate remote-management software, primarily DWAgent and AnyDesk, installed as services and staged in non-standard directories to resemble legitimate software.

Alongside the legitimate tooling, the operators deploy custom malware. A lightweight downloader tracked as Stagecomp, retrieved from attacker infrastructure, delivers a custom remote access trojan tracked as Darkcomp that impersonates a Microsoft WebView2 application, built from a trojanized sample project and signed with a revoked code-signing certificate. The implant employs multiple defense-evasion measures, including runtime resolution of its capabilities, sandbox and virtualization checks prior to execution, and an encrypted configuration file. The operators execute sequences of native discovery commands, move laterally using remote desktop and virtual private network access with the compromised accounts, and communicate with command-and-control infrastructure over HTTPS at a fixed polling interval, exfiltrating collected data over the same channel. No file-encryption payload has been observed across these intrusions, consistent with objectives of data theft and persistent access rather than service disruption.

SHA256 FILE HASH 6
24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14
a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0
1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6
3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90
c86ab27100f2a2939ac0d4a8af511f0a1a8116ba856100aae03bc2ad6cb0f1e0
cf3dfd1d6626fd2129abb7a5983c11827f4b0d497e2dba146a1889bd71f23cd5
IP ADDRESS 5
77.110.107.235
93.123.39.127
172.86.126.208
116.203.208.186
172.86.76.127
DOMAIN 8
adm-pulse.com
moonzonet.com
uploadfiler.com
serialmenot.com
uppdatefile.com
hptqq2o2qjva7lcaaq67w36jihzivkaitkexorauw7b2yul2z6zozpqd.onion
gitempire.s3.us-east-005.backblazeb2.com
elvenforest.s3.us-east-005.backblazeb2.com
URL 1
http://172.86.126.208:443/ms_upd.exe
FILE NAME 5
ms_upd.exe
DIDS.exe
Game.exe
WebView2.exe
visualwincomp.txt

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Credential Named Text File Created On Windows Endpoint
  • Multiple Native Discovery Commands Executed on Same Device in a Short Timeframe
  • Non Browser Process Beaconing to External Host at a Regular Interval
  • Silently Installed RMM via Command Line Interpreter
  • Microsoft Teams Chat Initiator Presenting IT Helpdesk Themed Identity
  • Authentication From a New Device or Location Shortly After External Teams Contact
  • Single Device Establishing Outbound RDP Sessions to Multiple Internal Hosts
  • Windows Service Installed From a Newly Created ProgramData Subfolder
  • Interpreter Process Injecting Code Into a Suspended Process