Briefing

MuddyWater Linked to Ransomware Attack Using Microsoft Teams, Rapid7 Reports

security
by [email protected] (The Hacker News) ·

Patch Microsoft Teams to block malicious links, enable MFA, and monitor Teams traffic for phishing.

What to do now

Patch Microsoft Teams to block malicious links, enable MFA, and monitor Teams traffic for phishing.

Summary

MuddyWater, also known as Mango Sandstorm, Seedworm, and Static Kitten, has been linked to a ransomware attack that Rapid7 identified in early 2026. The operation is described as a false‑flag campaign aimed at sowing confusion about the true origin of the breach. Attackers used social engineering tactics that exploited Microsoft Teams, sending phishing messages that prompted users to click malicious links. Once a link was clicked, the malware payload was delivered, encrypting files and demanding a ransom.

The incident underscores the growing threat of ransomware groups targeting collaboration platforms. Rapid7’s analysis shows that the attack began with a Teams message that appeared to come from a legitimate colleague, leveraging the platform’s native chat and file‑sharing features. The use of Teams as an attack vector demonstrates the need for tighter security controls on messaging services. Organizations that rely heavily on Teams should review their security settings and consider additional layers of protection.

Key changes

  • MuddyWater (aka Mango Sandstorm, Seedworm, Static Kitten) identified as Iranian state‑sponsored group
  • Attack used ransomware and is described as a false‑flag operation
  • Social engineering via Microsoft Teams phishing messages initiated the infection
  • Rapid7 observed the attack in early 2026
  • Malware payload delivered after link click, encrypting files
  • Teams chat and file‑sharing features were exploited as attack vector

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting