Iran cyberspies LARPing as ransomware crims in espionage ops

https://image.theregister.com/5222295.jpg?imageId=5222295&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Iran cybersnoops still LARPing as ransomware crooks in espionage ops

MOIS-linked cyber outfit puts on a ransomware show to disguise the wide-open backdoor behind the scenes

Researchers at Rapid7 say that they have spotted what they believe was an Iranian intelligence cyber unit masquerading as the Chaos ransomware gang to hide a state-sponsored espionage operation.

The intrusion was spotted earlier this year, and investigators say breadcrumbs left behind give them "medium confidence" in saying it was the work of MuddyWater, which has been linked to intrusions affecting Western government and banking networks in recent months.

Attackers began with a Microsoft Teams phishing campaign, which is not uncommon. They also encouraged targets to share their screens. Again, it was nothing too out of the ordinary.

However, what must have required some expert persuasion work was that they convinced these individuals to enter their credentials into local text files, and even modify...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE