Hackers Exploit Microsoft Teams to Steal Credentials and Bypass MFA

Iranian state-sponsored threat actors linked to MuddyWater (also tracked as Seedworm) have been caught using the Chaos ransomware brand as a false flag to conduct targeted espionage operations.

Rapid7 researchers uncovered the intrusion in early 2026, revealing a calculated campaign that weaponized Microsoft Teams as a phishing vector to steal credentials and manipulate multi-factor authentication (MFA) all while disguising intelligence-gathering objectives behind the appearance of a financially motivated ransomware attack.

MuddyWater is an advanced persistent threat (APT) group affiliated with Iran’s Ministry of Intelligence and Security (MOIS).

In this campaign, the group borrowed the branding of Chaos, a ransomware-as-a-service (RaaS) operation that emerged in February 2025 following law enforcement’s disruption of the BlackSuit ransomware infrastructure during Operation Checkmate.

Believed to include former BlackSuit and Royal ransomware members, Chaos specializes in big-game hunting attacks demanding ransoms of up to $300,000.

However, in this incident, the ransomware branding was purely a cosmetic cover for something far more dangerous.

Credential Theft and MFA Hijacking

The attack began with targeted social engineering via Microsoft Teams, in which threat actors sent external chat requests to employees.

Once contact was established, attackers initiated screen-sharing sessions to gain direct visibility into victim systems.

Users were then instructed to type their credentials into local text files named credentials.txt or cred.txt and add attacker-controlled devices to their MFA configurations, effectively handing over persistent authenticated access.

Attackers also directed victims to a phishing page at hxxps[://]adm-pulse[.]com/verify.php, which impersonated a Microsoft Quick Assist interface to harvest additional credentials.

With hijacked accounts in hand, the threat actors authenticated to internal systems, including a Domain Controller, established persistent remote access through RDP sessions, and deployed legitimate remote management tools DWAgent and AnyDesk to move laterally across the network.

Notably, the attackers deliberately avoided traditional ransomware encryption, a clear behavioral signal that financial gain was never the primary objective.

Beyond credential theft, the attackers deployed a sophisticated multi-stage malware chain. A downloader named ms_upd.exe was fetched via curl from a remote IP and executed on compromised machines.

This dropper then retrieved three components: WebView2Loader.dll (a legitimate Microsoft DLL used for blending), an encrypted configuration file named visualwincomp.txt, and Game.exe, a custom Remote Access Trojan (RAT) that impersonates a legitimate Microsoft WebView2 application.

Game.exe supports 12 commands, including arbitrary command execution, file upload and deletion, and interactive management of PowerShell and cmd.exe shells.

It communicates with the C2 server uploadfiler[.]com over port 443. The RAT also implements sandbox detection, VM detection, and anti-analysis techniques, including XOR-encoded strings and dynamic API resolution, making it resistant to automated analysis environments.

Several technical indicators supported attribution to MuddyWater. A code-signing certificate bearing the name “Donald Gay,” a known shared resource in MuddyWater’s toolkit previously tied to “Operation Olalampo” targeting U.S. and MENA organizations, was found embedded in the malware.

The C2 domain moonzonet[.]com, used by ms_upd.exe, was also independently linked to MuddyWater activity in early 2026.

Additional hallmarks include the group’s characteristic use of pythonw.exe for code injection and their established “IT Support” persona on Microsoft Teams, a social engineering tactic observed in prior campaigns.

The extortion emails and Chaos data-leak site listing appear designed to divert defenders’ attention toward ransomware recovery procedures while the attackers quietly maintained long-term persistence through remote access tools.

This mirrors a late 2025 incident in which MuddyWater was linked to the Qilin RaaS ecosystem in an attack targeting an Israeli organization.

Organizations should treat unsolicited Microsoft Teams messages from external accounts with extreme caution, especially any request for screen sharing or credential input.

Security teams should monitor for unexpected deployment of DWAgent or AnyDesk, unusual RDP activity on domain controllers, and any MFA configuration changes initiated by non-administrative users.

Most critically, this campaign reinforces that ransomware indicators alone cannot define the true scope of an intrusion; the full attack lifecycle must be examined to uncover the real objective.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories