
- Iranian APT MuddyWater posed as IT staff via Microsoft Teams, tricking victims into granting remote access
- They deployed infostealers, altered MFA, exfiltrated data, and staged a Chaos ransomware infection as cover
- Researchers concluded the true motive was espionage, not profit, highlighting state‑sponsored tradecraft overlap with criminal tactics
Iranian state-sponsored hackers ran a cyber-espionage campaign, and then tried to throw investigators off track with a ransomware infection, experts have warned.