MuddyWater Uses Teams to Harvest Credentials and Subvert MFA in Chaos False-Flag Campaign

1 min read
Source: CyberSecurityNews
MuddyWater Uses Teams to Harvest Credentials and Subvert MFA in Chaos False-Flag Campaign
Photo: CyberSecurityNews
TL;DR Summary

Security researchers describe a MuddyWater operation that exploited Microsoft Teams for external contact and screen-sharing to harvest user credentials (credentials.txt/cred.txt) and push MFA changes, followed by backdoor access using DWAgent and AnyDesk. The attackers deployed a custom RAT (Game.exe) and used C2 domains linked to MuddyWater, framing the intrusion as a Chaos ransomware false-flag campaign focused on credential theft and data exfiltration rather than encryption. The campaign featured indicators like a forged code-signing certificate and stolen credentials enabling lateral movement to Domain Controllers.

Share this article

Reading Insights

Total Reads

0

Unique Readers

18

Time Saved

60 min

vs 61 min read

Condensed

99%

12,02983 words

Want the full story? Read the original article

Read on CyberSecurityNews