Iranian government hackers using Chaos ransomware as cover, researchers say
2026-05-08T02:51:52Z•3d2b8ec8519bf361b676d2ed3e07e5fa00acac33304c77525884ee0476543d65
AI ActAPT37Android malwareBirdCallChaos ransomwareESETEU policyIranMOISMuddyWaterOT/ICSPolish intelligenceRapid7RussiaSupreme Courtdoxxingnudification toolsransomwarewater treatment
What happened
A set of mid-2026 cyber and policy developments: Rapid7 found an intrusion by MuddyWater (Iran-linked, MOIS) that used Chaos ransomware as a cover; Polish intelligence warned of attacks on water-treatment control systems amid heightened hostile activity (not publicly attributed but flagged Russian special services); ESET attributed an Android ‘BirdCall’ backdoor campaign targeting ethnic Koreans in China to APT37 via malicious card-game apps; a North Carolina man pleaded guilty to doxxing U.S. Supreme Court justices; and European leaders reached a tentative AI Act simplification deal that bans
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 3d2b8ec8519bf361b676d2ed3e07e5fa00acac33304c77525884ee0476543d65
- Enrichment time
- 2026-05-08T02:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.