MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
2026-05-06T19:24:15Z•a571968f9373e8b772bbeb1be5b66ba1af08dd55677dc241b600bf4bcfdf5d4b
Apache HTTP/2CloudZ RATDAEMON ToolsLinux LPEMOVEitMetInfoMicrosoft TeamsMuddyWaterPalo Alto PAN-OSRCEScarCruftSilver FoxTrellix breachWeaver E-cologyactive exploitationcredential theftfalse flagphishingransomwaresupply chain
What happened
A May 2026 news cluster highlights a surge in credential-theft, supply-chain compromises, and multiple critical vulnerabilities being actively exploited. Notable incidents include an attributed MuddyWater (Iranian) false-flag ransomware campaign using social engineering via Microsoft Teams to steal credentials; supply-chain compromises (DAEMON Tools, a gaming platform abused by ScarCruft) delivering backdoors; large-scale phishing operations (including campaigns targeting 35,000 users and 30,000 Facebook accounts); and a source-code breach at Trellix. Several high-severity vulnerabilities are:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- a571968f9373e8b772bbeb1be5b66ba1af08dd55677dc241b600bf4bcfdf5d4b
- Enrichment time
- 2026-05-06T19:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.