Skip to content
NetarxImpact Database
Help Desk ImpersonationNo AI reportedReportedCampaign

MuddyWater poses as IT support in Microsoft Teams to harvest credentials and add MFA devices

Multiple organisations in the United States and MENA (unnamed) · Manufacturing · United States and Middle East / North Africa · May 6, 2026

What happened

Rapid7 Labs published research on 6 May 2026 describing an intrusion that presented as a Chaos ransomware-as-a-service attack but was assessed with moderate confidence as a false-flag operation by the Iranian state-aligned group MuddyWater. The initial access was social engineering conducted entirely inside Microsoft Teams: the actors messaged employees while posing as IT support and used interactive screen sharing to harvest credentials and manipulate multi-factor authentication enrolment. No file encryption was executed; the operators focused on data exfiltration and persistence via DWAgent and AnyDesk. Rapid7 observed the campaign in early 2026 against US and MENA organisations, with the Chaos brand claiming 36 victims as of late March 2026.

How the deception worked

The operators contacted employees over Microsoft Teams, arriving as an internal-looking IT support persona rather than by email, which sidesteps mail security entirely and borrows the trust employees extend to the corporate chat client. They opened an interactive screen-sharing session, framed as troubleshooting, giving them live visibility of the victim's desktop. During the session they instructed the employee to type credentials into a text file where the attacker could read them, and to change MFA settings so an attacker-controlled device was enrolled as a valid second factor. That enrolment converted a one-off deception into durable authenticated access, after which remote access tooling was installed for persistence.

The control that would have caught it· our reading, not a claim from the sources

Blocking or strictly gating chat and screen share from external Microsoft Teams tenants, and alerting on any new MFA device enrolment, would cut off both the approach channel and the persistence step.

Sources (2)

  1. Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
    Rapid7 Labs·rapid7.comOpen ↗
  2. MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
    The Hacker News·thehackernews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.