Security researchers attribute a ransomware-related intrusion campaign to the Iranian state-sponsored hacking group MuddyWater (also tracked as Mango Sandstorm, Seedworm, and Static Kitten). The activity is described as a “false flag” operation in which attackers present their actions as being associated with ransomware, while using that framing to facilitate broader access and persistence.
According to reports from Rapid7 and Bleeping Computer, the campaign uses social engineering delivered through Microsoft Teams. In the observed sequence, messages and related tactics are used to initiate the infection chain and to gain access to victims. Once inside, the attackers establish persistence.
Bleeping Computer adds that the operation uses Chaos ransomware as a decoy, further contributing to the false-flag characterization. Across coverage, the common elements are the MuddyWater attribution, the use of Microsoft Teams for social engineering, and the deliberate use of ransomware-related lures rather than ransomware alone.
The reports describe the campaign as active in early 2026, based on researcher observations, and they focus on technique and attribution rather than disclosing victim identities or specific impact details.