ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME21:10:28 UTC
← All briefs
HIGHCyber IntelligenceFriday, May 8, 2026

Iranian intelligence operatives disguise espionage as ransomware attack

MuddyWater APT group deployed Chaos ransomware to mask intrusion tied to Iran's Ministry of Intelligence and Security, incident responders report.

Iranian state-sponsored hackers are using ransomware as operational camouflage, according to a report published by Rapid7. What initially appeared to be a Chaos ransomware infection was later attributed to MuddyWater, an advanced persistent threat group linked to Iran's Ministry of Intelligence and Security.

The tactic represents a shift in state-sponsored intrusion tradecraft. Rather than pursue data exfiltration or network persistence in silence, the operators deployed visible ransomware to obscure their true intent. Ransomware attacks typically draw attribution toward financially motivated cybercriminals, not intelligence services.

MuddyWater has operated since at least 2017, targeting telecommunications providers, government agencies, and critical infrastructure across the Middle East, Europe, and North America. The group is assessed by multiple Western intelligence agencies to work on behalf of Iran's MOIS.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01Organizations in government and telecom sectors face heightened risk of misattributed intrusions
  • 02Incident response teams must consider espionage motives even in apparent ransomware cases
  • 03Threat intelligence models relying on actor-tool correlation require recalibration
  • 04Insurance and legal frameworks may struggle to classify hybrid criminal-espionage incidents
Source
The Record
https://therecord.media/iran-government-hackers-use-chaos-ransomware-as-cover
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#iran#muddywater#ransomware#apt#mois#attribution
Related Briefs