Iranian government hackers using Chaos ransomware as cover, researchers say
2026-05-08T08:52:02Z•d33bcd5e2a9113251bd7250714a77b63e937786c6973271979b73241fc7e9eee
MOISai actandroid malwareapt37backdoorbirdcallchaos ransomwarecritical infrastructuredecember 2027doxxingeseteuiranjudiciarymudd ywaternorth koreanudification banpoland intelligencepolicy delayransomware-as-coverrapid7russia (suspected)sqgamesupreme courtwater treatment
What happened
Multiple security incidents and policy developments: Rapid7 reported an intrusion that mimicked Chaos ransomware but was attributed to MuddyWater (an Iranian APT linked to MOIS), indicating ransomware was used as operational cover. ESET attributed an Android ‘BirdCall’ malware campaign to North Korea’s APT37, which delivered a backdoor via a suite of card games from vendor Sqgame targeting ethnic Koreans in China. Polish intelligence warned of attacks on water-treatment control systems amid heightened hostile cyber activity (report mentions increased focus by Russian special services). SeparAT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- d33bcd5e2a9113251bd7250714a77b63e937786c6973271979b73241fc7e9eee
- Enrichment time
- 2026-05-08T08:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.