Skip to content
MuddyWater Behind Chaos Ransomware False Flag

MuddyWater Behind Chaos Ransomware False Flag

Socprime May 7, 2026

In early 2026, what initially appeared to be a routine Chaos ransomware incident was later identified as a false-flag operation tied to the Iranian state-linked group MuddyWater, also known as Seedworm. Rather than focusing on file encryption, the attackers used Microsoft Teams for social engineering, stole credentials and MFA tokens, and deployed a custom downloader together with a remote access trojan. The operation reused infrastructure associated with MuddyWater, including a code-signing certificate, and was geared toward data theft and persistent long-term access.

Rapid7 investigators reconstructed the intrusion chain from Teams-based credential theft to the use of legitimate remote administration tools such as AnyDesk and DWAgent, followed by delivery of ms_upd.exe , which retrieved a custom RAT named Game.exe . The team identified command-and-control domains including moonzonet.com and uploadfiler.com , along with multiple associated IP addresses and a signing certificate previously linked to MuddyWater. Malware analysis also uncovered anti-analysis behavior, a mutex used to enforce single execution, and persistence mechanisms involving a service and hidden files.

Organizations should enforce stronger MFA protections, restrict remote desktop access and Teams screen-sharing to trusted accounts, and monitor for legitimate remote access tools being used in unusual contexts. Application allow-listing should be applied to code-signed binaries, and execution of unsigned files from user-accessible directories should be blocked. Security teams should also audit certificate usage regularly and block the known malicious domains and IP addresses tied to the campaign.

If this activity is detected, isolate the affected systems immediately, revoke compromised credentials and MFA tokens, and begin full forensic collection. The identified command-and-control infrastructure should be blocked, AnyDesk and DWAgent services should be removed, and the custom RAT should be eradicated from the environment. Threat hunting should also be conducted for the mutex ATTRIBUTES_ObjectKernel and any remaining files stored under ProgramData .

Prerequisite: The Telemetry & Baseline Pre‑flight Check must have passed.

Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected by the detection logic.

Attack Narrative & Commands:

Regression Test Script:

Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.