Iranian APT Intrusion Masquerades as Chaos Ransomware Attack

https://www.securityweek.com/wp-content/uploads/2023/04/Iran-Cyberattacks.jpg

The Iran-linked APT actor MuddyWater has been observed performing an intrusion masquerading as a ransomware attack, Rapid7 reports.

As part of the intrusion observed in early 2026, the attackers relied on social engineering for initial access and performed operations typically associated with espionage campaigns, including reconnaissance, credential harvesting, and data theft, but did not deploy file-encrypting ransomware.

The threat actors engaged with the victim organization’s employees via Microsoft Teams, establishing screen-sharing sessions for access to users’ assets. This allowed them to steal credentials, manipulate MFA protections, and compromise accounts.

“While connected, the TA executed basic discovery commands, accessed files related to the victim’s VPN configuration, and instructed users to enter their credentials into locally created text files. In at least one instance, the TA also deployed a remote management tool (AnyDesk) to further facilitate access,” Rapid7 says.

Next, the attackers established persistent access through RDP sessions and the DWAgent remote...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more

https://cdn.arstechnica.net/wp-content/uploads/2026/06/Netflix-1152x648-1782496111.jpg

Netflix has been gradually requiring each profile under a Netflix subscription to use a unique email address; the rule doesn't apply to children's profiles

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.

https://assets.bwbx.io/images/users/iqjWHBFdfxIU/iMCFVYC_pczw/v0/1200x800.jpg

How AI is shaping the 2026 US midterms, as public anger grows against data center expansion and the AI industry emerges as one of the biggest financial backers

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.