PULSE NAME
IOC - Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
WHITE celestre 2026-05-15 Modified: 2026-05-15
19
IOCs
MEDIUM VOLUME
In early 2026, a sophisticated intrusion initially appearing to be a standard Chaos ransomware attack was assessed to be consistent with a targeted state-sponsored operation. While the threat actor operated under the banner of the Chaos ransomware-as-a-service (RaaS) group, forensic analysis revealed the incident was a "false flag" masquerade. Technical artifacts, including a specific code-signing certificate and Command-and-Control (C2) infrastructure, suggest with moderate confidence that this activity is linked to MuddyWater (Seedworm), an Iranian Advanced Persistent Threat (APT) affiliated with the Ministry of Intelligence and Security (MOIS).
Indicators of Compromise (5 / 19 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 1319d474d19eb386841732c728acf0c5fe64aa135101c6ceee1bd0369ecf97b6 2026-05-15
FileHash-SHA256 24857fe82f454719cd18bcbe19b0cfa5387bee1022008b7f5f3a8be9f05e4d14 2026-05-15
FileHash-SHA256 3df9dcc45d2a3b1f639e40d47eceeafb229f6d9e7f0adcd8f1731af1563ffb90 2026-05-15
FileHash-SHA256 a92d28f1d32e3a9ab7c3691f8bfca8f7586bb0666adbba47eab3e1a8faf7ecc0 2026-05-15
FileHash-SHA256 c86ab27100f2a2939ac0d4a8af511f0a1a8116ba856100aae03bc2ad6cb0f1e0 2026-05-15