Related Threat Clusters
-
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool
The Smoke#Screen campaign exploits social engineering tactics to install the legitimate ScreenConnect RMM tool on compromised systems, providing attackers with remote access. Targeting both Windows and macOS, the…
8 articles · Updated August 4, 2026 -
Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console
A vishing campaign, tracked as STAC4749, targeted North American organizations from February to June 2026, using Microsoft Teams to impersonate IT personnel and gain remote access. Attackers deployed a modular toolset,…
9 articles · Updated July 29, 2026 -
Chaos Ransomware Deploys msaRAT to Evade Detection via Browsers
The Chaos ransomware group has introduced a new Rust-based remote access trojan (RAT) named msaRAT, which disguises command-and-control (C2) traffic through legitimate web browsers like Chrome and Microsoft Edge. By…
8 articles · Updated July 23, 2026
Recent Intelligence Reports
- 826591 — www.cybersecuritydive.com · August 5, 2026
- A Two — Cybersecuritynews · July 30, 2026
- Chaos in Teams vishing — Sophos · July 28, 2026
- Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel — Cybersecuritynews · July 23, 2026
- MuddyWater hackers use Chaos ransomware as a decoy in attacks — Bleepingcomputer · May 6, 2026