MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

2026-05-06T19:24:15Za571968f9373e8b772bbeb1be5b66ba1af08dd55677dc241b600bf4bcfdf5d4b
Apache HTTP/2CloudZ RATDAEMON ToolsLinux LPEMOVEitMetInfoMicrosoft TeamsMuddyWaterPalo Alto PAN-OSRCEScarCruftSilver FoxTrellix breachWeaver E-cologyactive exploitationcredential theftfalse flagphishingransomwaresupply chain

What happened

A May 2026 news cluster highlights a surge in credential-theft, supply-chain compromises, and multiple critical vulnerabilities being actively exploited. Notable incidents include an attributed MuddyWater (Iranian) false-flag ransomware campaign using social engineering via Microsoft Teams to steal credentials; supply-chain compromises (DAEMON Tools, a gaming platform abused by ScarCruft) delivering backdoors; large-scale phishing operations (including campaigns targeting 35,000 users and 30,000 Facebook accounts); and a source-code breach at Trellix. Several high-severity vulnerabilities are:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a571968f9373e8b772bbeb1be5b66ba1af08dd55677dc241b600bf4bcfdf5d4b
Enrichment time
2026-05-06T19:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack · Baitaphish