DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // MUDDYWATER-CHAOS-FALSEFLAGFIRST SEEN: 2017 (Operation Olalampo variant: JAN 2026)

MuddyWater (Operation Olalampo — Chaos Ransomware False Flag)

ALSO KNOWN AS: Seedworm, MERCURY, Static Kitten, TEMP.Zagros, ITG17
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Iran (Ministry of Intelligence and Security — MOIS)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:2017 (Operation Olalampo variant: JAN 2026)
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL79/100
RESOURCES87/100
PERSISTENCE87/100
STEALTH87/100
IMPACT79/100

Rapid7 disclosed in May 2026 that MuddyWater (Seedworm) conducted a sophisticated false-flag ransomware operation in early 2026, operating under the Chaos RaaS banner while forensic analysis revealed MOIS-linked code-signing certificates ('Donald Gay' + 'Amy Cherne' cert cluster) tying the intrusion to Operation Olalampo. The group used interactive Microsoft Teams sessions to harvest MFA credentials under an 'IT Support' social engineering persona. This marks a significant evolution: MuddyWater adopting a commercially available RaaS brand to project a cybercriminal identity while conducting intelligence-driven targeted operations, blurring the line between espionage and ransomware.

Espionage and pre-positioning for disruptive operations; use of ransomware as false flag to complicate attribution and obscure MOIS operational intent

Chaos RaaS false-flag deployment, MOIS code-signing certificate reuse ('Donald Gay'/'Amy Cherne' certs), Microsoft Teams interactive screen-sharing MFA harvesting, pythonw.exe process injection into suspended processes, triple/quadruple extortion threats (DDoS, customer notification), 'blind' countdown timer DLS technique to accelerate negotiation, social engineering IT support persona

GOVERNMENT
DEFENSE
TECHNOLOGY
FINANCIAL SERVICES
CRITICAL INFRASTRUCTURE

Chaos RaaS infrastructure (DLS with blind countdown timers); MOIS-linked code-signing certs cross-referenced in Operation Olalampo attribution; pythonw.exe injection chain; C2 consistent with prior MuddyWater MOIS infrastructure clusters

FILE DATE: JAN 2026
Operation Olalampo — Chaos Ransomware False Flag
MuddyWater operated under the Chaos RaaS banner in targeted intrusions against US and Western organizations, using Teams-based MFA harvesting and MOIS code-signing certificates, publicly disclosed by Rapid7 in May 2026 with moderate-confidence attribution.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn