{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials"},"incident":{"slug":"2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials","title":"MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices","date":"2026-05-06","date_precision":"day","year":2026,"victim_org":"Multiple organisations in the United States and MENA (unnamed)","sector":"Manufacturing","country":"United States and Middle East / North Africa","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"MuddyWater (Seedworm), assessed as linked to Iran's Ministry of Intelligence and Security, operating behind Chaos ransomware branding","summary":"Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.","how_it_worked":"The operators contacted employees over Microsoft Teams, arriving as an internal-looking IT support persona rather than by email, which sidesteps mail security entirely and borrows the trust employees extend to the corporate chat client. They opened an interactive screen-sharing session, framed as troubleshooting, giving them live visibility of the victim's desktop. During the session they instructed the employee to type credentials into a text file where the attacker could read them, and to change MFA settings so an attacker-controlled device was enrolled as a valid second factor. That enrolment converted a one-off deception into durable authenticated access, after which remote access tooling was installed for persistence.","lessons":"Blocking or strictly gating chat and screen share from external Microsoft Teams tenants, and alerting on any new MFA device enrolment, would cut off both the approach channel and the persistence step.","confidence":"Reported","sources":[{"title":"Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware","url":"https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/","publisher":"Rapid7 Labs"},{"title":"MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack","url":"https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-muddywater-poses-as-it-support-in-microsoft-teams-to-harvest-credentials"}}