Iranian government hackers using Chaos ransomware as cover, researchers say

2026-05-08T02:51:52Z3d2b8ec8519bf361b676d2ed3e07e5fa00acac33304c77525884ee0476543d65
AI ActAPT37Android malwareBirdCallChaos ransomwareESETEU policyIranMOISMuddyWaterOT/ICSPolish intelligenceRapid7RussiaSupreme Courtdoxxingnudification toolsransomwarewater treatment

What happened

A set of mid-2026 cyber and policy developments: Rapid7 found an intrusion by MuddyWater (Iran-linked, MOIS) that used Chaos ransomware as a cover; Polish intelligence warned of attacks on water-treatment control systems amid heightened hostile activity (not publicly attributed but flagged Russian special services); ESET attributed an Android ‘BirdCall’ backdoor campaign targeting ethnic Koreans in China to APT37 via malicious card-game apps; a North Carolina man pleaded guilty to doxxing U.S. Supreme Court justices; and European leaders reached a tentative AI Act simplification deal that bans

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
3d2b8ec8519bf361b676d2ed3e07e5fa00acac33304c77525884ee0476543d65
Enrichment time
2026-05-08T02:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.