An employee gets a Teams message from what looks like IT support. Screen sharing request. While they’re connected, they’re asked to type their credentials into a text file (credentials.txt, saved on their own desktop). Then add a new device to their MFA. The “helpdesk session” ends. The access doesn’t.
Rapid7 has linked this technique to MuddyWater, the Iranian state-sponsored APT attributed to the Ministry of Intelligence and Security (MOIS), operating under a Chaos ransomware false flag. The intrusions were designed to look like opportunistic criminal activity. They weren’t.
What the False Flag Actually Tells You
Chaos ransomware artefacts were present on compromised systems. No files were encrypted. That’s the diagnostic: a genuine ransomware affiliate deploys the encryptor. A state actor who wants to look like a ransomware affiliate leaves the tooling on disk and doesn’t use it.
The objective was credential collection, persistent access, and data exfiltration, consistent with an intelligence mandate, not an extortion one. The Chaos branding was cover. Organisations that responded to this as a ransomware incident (engaging criminal extortion playbooks, focusing on recovery, negotiating) were applying the wrong framework to a state-actor intrusion.
That distinction matters in practice. A criminal ransomware group’s access ends when you recover or pay. A state actor’s implants may persist through apparent remediation, because the objectives were different from the start.
Attribution
Rapid7’s attribution rests on a specific code-signing certificate and C2 infrastructure. The moonzonet[.] domain used during this campaign previously appeared in confirmed MuddyWater operations targeting Israeli and Western organisations earlier in 2026. MuddyWater is also tracked as Seedworm, Mango Sandstorm, and Static Kitten across different vendor taxonomies. Attribution confidence is moderate: the technical linkages are present, the C2 overlap is specific, but MuddyWater attribution carries the usual caveats about shared infrastructure.
Who Got Targeted
Construction, manufacturing, and business services organisations across the US and several European countries: the UK, Sweden, Austria, Germany, Poland, and Italy. Not classic CNI targeting. But manufacturing companies hold IP and supply-chain relationships that are of consistent intelligence value to Iranian state actors, and business services firms often have privileged access to clients in sectors Iran does care about more directly.
The Teams Vector Is the Real Finding Here
Most organisations’ phishing defences are built for email. Teams-based social engineering exploits a gap: employees apply different scrutiny to a request arriving in what feels like an internal helpdesk channel. An email asking you to type your credentials into a text file would get flagged. The same request in a screen-sharing session with someone who sounds like IT support is processed differently.
The false flag technique itself isn’t new; Sandworm has used it. But Iranian APTs adopting this level of operational cover reflects a genuine maturation in tradecraft. The combination of Teams social engineering, credential harvesting without malware, and ransomware-branded infrastructure to misdirect incident response is a more sophisticated playbook than MuddyWater was running three years ago.
Immediate Checks
Teams external access settings. Can guests or federated external users initiate screen-sharing sessions with your employees? If the answer is yes and that permission wasn’t deliberate, review it. Most organisations haven’t thought specifically about this.
MFA device registrations for the last 90 days. Look for any authenticator device additions that weren’t provisioned through standard IT workflows. That’s the persistent access the campaign was establishing. It may already be there.
Hunt the moonzonet C2 domain and associated IP infrastructure in DNS query logs and proxy logs. Rapid7 has published IOCs. This takes an hour. Do it.
If Chaos ransomware indicators are present in your environment without active encryption, treat the incident as a potential state-actor intrusion from the first triage step. Preserve forensic evidence. Don’t let a criminal response playbook set the tempo for what may be a very different situation.