MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering, DWAgent Persistence, Game.exe RAT Trojanizing Microsoft WebView2APISample (Operation Olalampo Link) — Threadlinqs Intelligence
As of 2026-05-30, MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering, DWAgent Persistence, Game.exe RAT Trojanizing Microsoft WebView2APISample (Operation Olalampo Link) is a high-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-0468 · Severity: HIGH · Status: MONITORING · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Rapid7 disclosed a state-sponsored intrusion attributed with moderate confidence to MuddyWater (Seedworm), an Iranian MOIS-affiliated APT, that masqueraded as a Chaos ransomware-as-a-service attack.
On 2026-05-06 Rapid7's Threat Research team published 'Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware', documenting a multi-stage intrusion that publicly presented as a Chaos ransomware-as-a-service (RaaS) operation but was technically and organizationally linked with moderate confidence to MuddyWater (Seedworm), an Iranian APT linked to the Ministry of Intelligence and Security (MOIS). The activity overlaps with MuddyWater's broader 2026 Operation Olalampo targeting United States and MENA organizations across construction, manufacturing, and business services verticals.
Initial access was obtained through interactive Microsoft Teams 1:1 chats originated from an attacker-controlled Teams account impersonating an internal IT support persona that MuddyWater has refined throughout 2026. The actor invoked Teams screen-sharing to walk targets through a Quick Assist-themed phishing page hosted at hxxps://adm-pulse[.]com/verify.php, instructing victims to type credentials into local text files (credentials.txt, cred.txt) and to add attacker-controlled devices to their MFA configuration. The Teams sessions originated from 77.110.107.235 and 93.123.39.127.
Once credentials and MFA were compromised, the operator established hands-on-keyboard footholds via RDP and deployed two legitimate remote-access tools — AnyDesk (bfc1675ee1e358db8356f515aaded7962923e426aa0a0a1c0eddfc4dab053f89) and DWAgent (dwagent.exe / dwagsvc.exe / dwaglnc.exe) — to provide redundant persistence channels resilient to credential resets. A renamed pythonw.exe (cf3dfd1d6626fd2129abb7a5983c11827f4b0d497e2dba146a1889bd71f23cd5) shipped with the DWAgent bundle was used for in-memory code injection and beaconed to 116.203.208.186.
From the foothold, the actor used curl to download ms_upd.exe (24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14) from 172.86.126.208. The downloader uses a /register, /check, /status registration flow against moonzonet[.]com, then fetches three secondary components — Game.exe (1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6) renamed from a benign Microsoft WebView2 binary, a side-loaded WebView2Loader.dll (a47cd0dc12f0152d8f05b79e5c86bac9231f621db7b0e90a32f87b98b4e82f3a), and visualwincomp.txt (c86ab27100f2a2939ac0d4a8af511f0a1a8116ba856100aae03bc2ad6cb0f1e0), an AES-256-GCM encrypted configuration containing the C2 hostname uploadfiler[.]com and port. After staging, ms_upd.exe self-deletes via the well-worn 'cmd.exe /c ping 127.0.0.1 -n 6 > nul && del' technique.
Game.exe is a custom RAT trojanized from Microsoft's open-source WebView2APISample project (PDB path: C:\Users\pc\Downloads\WebView2Samples-main\...\Release\x64\WebView2APISample.pdb). It establishes persistence in C:\ProgramData\visualwincomp-<random>\, enforces single-instance execution via the ATTRIBUTES_ObjectKernel mutex, polls /index.php on its C2 every 60 seconds, and exposes 12 core operator commands (run_cmd, run_powershell, upload, upload_chunk, delete_file, cmd_start, cmd_input, cmd_stop, ps_start, ps_input, ps_stop, re_register). Anti-analysis covers dynamic API/DLL resolution (T1027.007), sandbox detection (sbiedll.dll, dbghelp.dll, api_log.dll, vmcheck.dll, wpespy.dll), VM-string checks (Virtual, VMWare, KVM, Hyper-V) using XOR key 0xAB, removable-drive enumeration, and time-based sleep skews (T1497.003). Rapid7 notes inconsistent tradecraft — XOR-encoded VM strings beside plaintext file paths and command opcodes, and dynamic Sleep() resolution despite static imports — characterizing the developer as 'unseasoned' relative to mature MuddyWater tooling.
Attribution rests primarily on the 'Donald Gay' code-signing certificate (issuer: Microsoft ID Verified CS AOC CA 02; thumbprint: B674578D4BDB24CD58BF2DC884EAA658B7AA250C; algorithm: sha384RSA; serial: 33 00 07 9A 51 C7 06 3E 66 05 3D 22 9B 00 00 00 07 9A 51), a Microsoft-issued Authenticode certificate previously documented as a shared MuddyWater resource pair
Target sectors: construction, manufacturing, business services, government, energy, telecommunications
Target regions: United States, Middle East, North Africa, MENA
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566, T1078, T1133, T1059, T1059.001, T1204, T1543, T1133, T1547, T1078