Iranian government hackers using Chaos ransomware as cover, researchers say

2026-05-08T08:52:02Zd33bcd5e2a9113251bd7250714a77b63e937786c6973271979b73241fc7e9eee
MOISai actandroid malwareapt37backdoorbirdcallchaos ransomwarecritical infrastructuredecember 2027doxxingeseteuiranjudiciarymudd ywaternorth koreanudification banpoland intelligencepolicy delayransomware-as-coverrapid7russia (suspected)sqgamesupreme courtwater treatment

What happened

Multiple security incidents and policy developments: Rapid7 reported an intrusion that mimicked Chaos ransomware but was attributed to MuddyWater (an Iranian APT linked to MOIS), indicating ransomware was used as operational cover. ESET attributed an Android ‘BirdCall’ malware campaign to North Korea’s APT37, which delivered a backdoor via a suite of card games from vendor Sqgame targeting ethnic Koreans in China. Polish intelligence warned of attacks on water-treatment control systems amid heightened hostile cyber activity (report mentions increased focus by Russian special services). SeparAT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
d33bcd5e2a9113251bd7250714a77b63e937786c6973271979b73241fc7e9eee
Enrichment time
2026-05-08T08:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iranian government hackers using Chaos ransomware as cover, researchers say · Baitaphish