Iran State-Linked Hackers Hid Espionage Campaign Behind Chaos Ransomware

Rapid7 says attackers tied to Iran’s MuddyWater group used ransomware branding as cover for a stealth cyber-espionage operation targeting Western networks

Iran State-Linked Hackers Hid Espionage Campaign Behind Chaos Ransomware

Illustration: Mikhail Nilov via Pexels.com

What initially appeared to be a routine ransomware attack was likely a covert Iranian cyber-espionage operation disguised as criminal activity, according to a new report by Rapid7.

The incident, uncovered earlier this year, involved hackers operating under the name of the Chaos ransomware group, a cybercriminal organization known for extortion attacks against businesses in the United States. But investigators say the operation bore the hallmarks of MuddyWater, an advanced hacking group tied to Iran’s Ministry of Intelligence and Security (MOIS).

Rather than focusing on encrypting files for ransom, as traditional ransomware gangs typically do, the attackers appeared more interested in quietly stealing data, maintaining long-term access to networks and disguising their true identity.

According to the research, “This activity is best understood as a hybrid intrusion model, in which ransomware is leveraged not as an end goal but as a mechanism for concealment, coercion and operational flexibility within a broader intelligence-driven campaign.”

The report explains that hackers gained access through social engineering conducted over Microsoft Teams. Employees at the targeted organization received chat requests from accounts posing as IT support staff. During screen-sharing sessions, victims were tricked into revealing passwords and even modifying multi-factor authentication settings to give attackers access.

Once inside the network, the hackers used legitimate remote-access tools such as DWAgent and AnyDesk to move through systems undetected. The attackers later claimed to have stolen sensitive data and attempted ransom negotiations, but notably never deployed file-encrypting malware – a major clue that financial profit was likely not the primary objective.

Rapid7 said several technical indicators linked the operation to the well-known APT group MuddyWater, including infrastructure and digital certificates previously associated with Iranian cyber campaigns targeting US, Israeli, and Middle Eastern organizations.

The report highlights what cybersecurity experts increasingly describe as a growing convergence between state-sponsored hacking and cybercrime. Governments are increasingly adopting the tactics and branding of ransomware gangs to create confusion, complicate attribution and delay defensive responses.

The findings also underscore how modern cyberattacks often rely less on sophisticated malware and more on manipulating people, particularly through trusted workplace communication tools already embedded in daily business operations.