MuddyWater hackers use Chaos ransomware as a decoy in attacks

2026-05-06T13:23:33Ze094fc73920ebcaf215b38722b5dc7a16b74a74c44da8f89296559739e6da82a
BirdCallCVE-2026-22679ChaosCloudZDAEMON ToolsInstructure breachLinux malwareMicrosoft Phone LinkMicrosoft TeamsMuddyWaterPAN-OSPalo Alto NetworksQuasar LinuxRCESMS/OTP theftScarCrft/APT37ShinyHuntersVimeoWeaver E-cologybackdoordata-breachransomwaresocial-engineeringsupply-chainzero-day

What happened

A batch of BleepingComputer stories highlights multiple active threats and high-impact incidents: Iran-linked MuddyWater actors used a Chaos ransomware decoy and Microsoft Teams social engineering to gain access and persistence; Palo Alto Networks warned of an actively exploited, unpatched PAN-OS User‑ID Authentication Portal RCE zero-day; a critical Weaver E‑cology bug (CVE-2026-22679) is being exploited in the wild; DAEMON Tools installers were trojanized in a supply‑chain campaign delivering backdoors to thousands of systems; a new Quasar Linux implant targets software developers with rootk

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
e094fc73920ebcaf215b38722b5dc7a16b74a74c44da8f89296559739e6da82a
Enrichment time
2026-05-06T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · MuddyWater hackers use Chaos ransomware as a decoy in attacks · Baitaphish