惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks
B
Blog
腾讯CDC
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - Franky
罗磊的独立博客
月光博客
月光博客
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
D
Docker
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
G
Google Developers Blog
V
Visual Studio Blog
I
InfoQ
有赞技术团队
有赞技术团队
D
DataBreaches.Net
Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Iran-sponsored threat group behind false flag social engi...
David Jones · 2026-05-06 · via Cybersecurity Dive - Latest News

An article from site logo

The state-linked actor has been masquerading as a criminal ransomware group in attacks targeting U.S. organizations.

Published May 6, 2026

The Strait of Hormuz shown by a satellite image in 2020, with the Persian Gulf and Gulf of Oman on each side.

The Strait of Hormuz between Oman and Iran shown by satellite in 2020. A threat group backed by Iranian intelligence is linked to a false flag hacking campaign targeting U.S. entities. Retrieved from NASA's Moderate Resolution Imaging Spectroradiometer.

A threat group linked to Iranian intelligence has been running a months-long false-flag operation to hack organizations in the U.S. and other countries under the guise of a criminal ransomware group, according to a report released Wednesday by researchers at Rapid7. 

The state-sponsored threat group, tracked as MuddyWater, operated a social engineering campaign beginning in early 2026 that abused Microsoft Teams to harvest credentials and bypass multifactor authentication. 

The attacks were made to look as if they were the work of Chaos, a ransomware-as-a-service group that has been active since 2025. Researchers said the false flag creates ambiguity that could affect how security teams investigate an intrusion. 

“If an operation looks like ransomware, defenders may initially treat it as financially motivated cybercrime rather than a state-linked operation,” Christiaan Beek, vice president of cyber intelligence at Rapid7, told Cybersecurity Dive. “That can slow attribution, complicate response, and give the actor plausible deniability.”

The Chaos group emerged after an international law enforcement operation, called Operation Checkmate, took down the infrastructure behind BlackSuit ransomware group. According to the Justice Department, BlackSuit, also known as Royal, was linked to about 450 attacks since 2022, with extortion proceeds of more than $370 million. 

Chaos ransomware has used voice-phishing and IT impersonation to initiate attacks and the group advertises its RaaS services on underground forums, according to Rapid7. As of March, the group had claimed 36 victims, mostly in construction, manufacturing and business services, with the majority of attacks in the U.S.

The recent MuddyWater attacks appear to be aimed at organizations of strategic value to Iran, including some government targets, according to Rapid7.

The social engineering attacks by MuddyWater used Microsoft Teams to reach employees at a targeted organization with chat requests. Hackers launched screen sharing sessions with the victims, who were told to enter credentials into a locally created text file. Hackers used those credentials to bypass multifactor authentication.

A remote access tool called DWAgent was used to gain persistence before the use of malware. A custom remote access Trojan called Game.exe was also found. 

Threat groups have engaged in similar diversionary tactics in the past. Researchers said despite the deceptive tactics to present the attacks as Chaos ransomware, the recent attacks have a digital signature affiliated with Iran’s Ministry of Intelligence and Security.

Beyond the attacks against U.S. targets, telemetry shows targeting in other regions, including the Middle East and South Asia. Specific attacks were located against targets in Jordan and Australia