MuddyWater Linked to Ransomware Attack Using Microsoft Teams, Rapid7 Reports
Patch Microsoft Teams to block malicious links, enable MFA, and monitor Teams traffic for phishing.
Patch Microsoft Teams to block malicious links, enable MFA, and monitor Teams traffic for phishing.
Summary
MuddyWater, also known as Mango Sandstorm, Seedworm, and Static Kitten, has been linked to a ransomware attack that Rapid7 identified in early 2026. The operation is described as a false‑flag campaign aimed at sowing confusion about the true origin of the breach. Attackers used social engineering tactics that exploited Microsoft Teams, sending phishing messages that prompted users to click malicious links. Once a link was clicked, the malware payload was delivered, encrypting files and demanding a ransom.
The incident underscores the growing threat of ransomware groups targeting collaboration platforms. Rapid7’s analysis shows that the attack began with a Teams message that appeared to come from a legitimate colleague, leveraging the platform’s native chat and file‑sharing features. The use of Teams as an attack vector demonstrates the need for tighter security controls on messaging services. Organizations that rely heavily on Teams should review their security settings and consider additional layers of protection.
Key changes
- MuddyWater (aka Mango Sandstorm, Seedworm, Static Kitten) identified as Iranian state‑sponsored group
- Attack used ransomware and is described as a false‑flag operation
- Social engineering via Microsoft Teams phishing messages initiated the infection
- Rapid7 observed the attack in early 2026
- Malware payload delivered after link click, encrypting files
- Teams chat and file‑sharing features were exploited as attack vector