Ransomware Persona Masks MuddyWater Espionage Operation

The real shift is not another Teams intrusion. It is that Rapid7 now ties the Chaos ransomware persona to MuddyWater through a code-signing certificate and C2 overlap, which turns what looks like extortion into state-backed espionage with deniability. Rapid7 says the campaign used Microsoft Teams screen sharing to harvest credentials and manipulate MFA, then kept access with DWAgent and AnyDesk, exfiltrated data, and sent ransom emails without deploying file-encrypting ransomware. The evidence points to a false-flag operation built to confuse incident response and make a spying campaign look like ordinary ransomware.

Part of the PlainSec briefing for 2026-05-07

Every edition of this story: Ransomware Persona Masks MuddyWater Espionage Operation

Sources