MuddyWater hackers use Chaos ransomware as a decoy in attacks
Source: BleepingComputer · Category: Threat Actor & Campaign
MuddyWater (Iranian state-linked group) disguises cyber operations as Chaos ransomware attacks using Microsoft Teams social engineering to establish persistence. Law firms are high-value targets for nation-state reconnaissance; monitor Teams for suspicious sharing, external collaboration, and unusual admin activity.