Skip to content
Iranian cyber espionage disguised as a Chaos Ransomware attack

Iranian cyber espionage disguised as a Chaos Ransomware attack

Securityaffairs.Co Pierluigi Paganini May 6, 2026

Iran-linked APT MuddyWater used ransomware-style tactics to mask espionage, combining phishing, credential theft, data exfiltration, and extortion without encryption. A newly discovered cyber intrusion attributed to the Iran-linked APT MuddyWater (aka SeedWormTEMP.ZagrosMango SandstormTA450, and Static Kitten) reveals how state- attackers are increasingly leveraging ransomware tactics to disguise espionage operations. The campaign, uncovered by security researchers at Rapid7, blended […]