Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Iranian state-sponsored group MuddyWater, operating under Iran’s Ministry of Intelligence and Security, conducted a targeted espionage campaign using Microsoft Teams to impersonate IT helpdesk staff and trick employees into granting remote access. Once inside, operators stole credentials, moved laterally across networks, and deployed Chaos ransomware as a cover story to disguise the true objective: intelligence gathering and espionage collection. Organizations using Microsoft Teams with external access enabled, particularly those in sectors of interest to Iranian intelligence, face direct risk of credential theft, data exfiltration, and prolonged undetected intrusion.

Author

Tech Jacks Solutions