ransomware
MuddyWater Poses as Chaos Ransomware to Hide Iran Espionage
2026-06-25

Espionage crews have worked out a useful trick. If you want to hide a state-backed intrusion, dress it up as a ransomware job and let the investigators chase the wrong story.
A new report from NCC Group lays out how MuddyWater, a group linked to Iran's Ministry of Intelligence and Security, recently impersonated the Chaos ransomware gang. Not a quick paint job either. They wrote extortion notes, opened victim negotiation channels, and posted targets to the Chaos leak site. The whole criminal pantomime was staged to convince responders they were dealing with money-motivated crooks, not spies.
Why bother with the costume?
Because attribution drives response. If your incident team thinks they're looking at Chaos, they're checking for data exfiltration tied to extortion, watching the negotiation chat, and planning around a payment decision. They are probably not assuming the negotiator is a foreign intelligence officer using the chat to buy time while files quietly leave the building.
NCC's Matt Hull puts it bluntly: the old wall between financially motivated ransomware and nation-state operations is coming down. The groups share infrastructure. They buy the same off-the-shelf tooling. And they have realised that borrowing a known criminal brand is a cheap, effective way to muddy attribution and slow the defender's response.
It's not just Iran
The report notes that one Iranian group has reportedly partnered with Russian cybercriminals to use a dark-web remote access trojan against espionage targets. China, Russia and North Korea have all been spotted running ransomware-as-a-service campaigns as cover for data theft. Ransomware, in other words, is becoming a useful uniform that anyone can put on.
This matters because the ransom note has, for years, been treated as a tell. Find a Chaos note, assume Chaos. Find LockBit branding, assume LockBit. That shortcut is now an actively exploited weakness.
What defenders are actually being asked to do
NCC's advice steers away from signature-matching and towards behaviour and context. A few things follow from that:
- Treat the ransom note as a claim, not a conclusion. Branding is cheap. Behaviour is harder to fake.
- Look at what's leaving the network, not just what's being encrypted. Quiet, targeted exfiltration during a noisy negotiation is the giveaway.
- Lean on adversary context. Who else has this tooling been seen with? Does the victim profile fit the supposed crew's usual targeting?
The Chaos impersonation is a tidy example of a wider shift. Ransomware groups, contractor crews and state services are increasingly drinking from the same pool of tools and tradecraft. The criminal brand on the screen is now part of the deception, and treating it as ground truth is how you miss the actual operation taking place underneath.