Threat actor
MuddyWater
Tracked by CyberSIXT since May 6, 2026 · last activity May 26, 2026
Coverage timeline
-
MuddyWater Uses DLL Side Loading in Nine Nation Espionagethehackernews.com · May 26, 2026
-
Iranian spies fake Chaos ransomware to steal data via Teamssecurityaffairs.com · May 6, 2026
-
MuddyWater hijacks Teams to spread Chaos ransomware false flagthehackernews.com · May 6, 2026
-
Iran-linked MuddyWater fakes Chaos ransomware in 2026 breachwww.securityweek.com · May 6, 2026