MuddyWater Breaches Oman Ministry and UAE Port Using Microsoft Teams in False Flag Attack
Iranian state-backed group MuddyWater used Microsoft Teams screen-sharing to harvest credentials in a false flag operation disguised as ransomware. Oman's Ministry of Justice lost 26,000 records. The Port of Fujairah in the UAE was breached, leaking 11,000 sensitive shipping documents.

Dark enterprise server room with a Microsoft Teams session visible on a monitor representing the MuddyWater false flag credential harvesting campaign targeting GCC government institutions
The Iranian state-sponsored threat group MuddyWater, also tracked as Mango Sandstorm, Seedworm, and Static Kitten, has been linked to a sophisticated false flag operation that used Microsoft Teams to harvest credentials and establish long-term persistence in victim environments, while masquerading as a financially motivated ransomware group to obscure attribution.
The intrusion was analysed by Rapid7, which found the campaign leveraged social engineering via Teams to initiate the infection sequence. Although the attack initially appeared consistent with the Chaos ransomware-as-a-service group, technical evidence confirmed it was a targeted, state-backed operation designed to look like opportunistic extortion.
The same reporting period also saw a parallel Iranian-nexus operation targeting Oman's government infrastructure, and a claimed breach of the Port of Fujairah in the UAE, both of which represent direct and material threats to GCC enterprise and government security.
How the Attack Worked: Microsoft Teams as an Entry Point
The campaign began with external chat requests sent via Microsoft Teams to target employees. Threat actors posed as IT support personnel and used interactive screen-sharing sessions to manipulate users into entering their credentials into locally created text files, effectively bypassing multi-factor authentication.
"The campaign was characterised by a high-touch social engineering phase conducted via Microsoft Teams, where the attackers utilised interactive screen-sharing to harvest credentials and manipulate multi-factor authentication. Once inside, the group bypassed traditional ransomware workflows, forgoing file encryption in favour of data exfiltration and long-term persistence via remote management tools like DWAgent." - Rapid7 Threat Intelligence Report, 2026
Using compromised user accounts, the threat actors conducted reconnaissance, deployed remote management tools including DWAgent and AnyDesk, moved laterally through the environment, and exfiltrated data before initiating ransom negotiations via email. File encryption, typically the defining characteristic of ransomware operations, was notably absent despite Chaos ransomware artefacts being present in the environment.
Rapid7 assessed that the ransomware component likely functioned primarily as an obfuscation mechanism rather than the primary objective, designed to focus defensive efforts on immediate financial impact and delay identification of the deeper persistence mechanisms.
The Malware Chain: Stagecomp and Darkcomp
Following initial access, the threat actor used RDP to download a binary identified as ms_upd.exe from an external server. This executable, referred to as Stagecomp, collects system information and connects to a command-and-control server to drop further payloads.
The primary second-stage payload, game.exe or Darkcomp, is a bespoke remote access trojan that masquerades as a legitimate Microsoft WebView2 application using a trojanised version of the official WebView2APISample project. Once deployed, the RAT enters a persistent polling loop, checking for new commands every 60 seconds and capable of executing PowerShell scripts, performing file operations, and spawning interactive shells.
Attribution to MuddyWater was confirmed through a code-signing certificate attributed to "Donald Gay" used to sign the initial dropper, a certificate previously identified in connection with the group's CastleLoader downloader known as Fakeset.
Oman Government Breach: 26,000 Records Exfiltrated
Running concurrently with the Teams-based intrusion campaign, threat intelligence firm Hunt.io identified a separate Iranian-nexus operation targeting Omani government institutions. An open directory on a RouterHosting VPS based in the United Arab Emirates surfaced an active intrusion campaign against the Omani Ministry of Justice and Legal Affairs, with the full toolkit, command-and-control code, session logs, and exfiltrated data exposed in plain sight.
The exfiltrated data included more than 26,000 Ministry of Justice user records, judicial case data, committee decisions, and SAM and SYSTEM registry hives, representing a significant and targeted intelligence collection operation against a GCC government institution.
Port of Fujairah, UAE: 11,000 Documents Compromised
The pro-Iran-aligned hacktivist group Handala Hack separately claimed to have gained access to the internal systems of the Port of Fujairah in the UAE, leaking approximately 11,000 sensitive documents including invoices, shipping records, and customs documentation.
Sergey Shykevich, Group Manager at Check Point Research, described the significance of this development:
"The claimed attack on the Port of Fujairah is that escalation, if confirmed. What's changed is the nature of the threat: this is no longer about intelligence gathering or public embarrassment. The cyber and kinetic domains are now explicitly connected. This campaign is not slowing down. Every quiet period on the physical front has historically been followed by intensified cyber activity and what we are seeing now is the most serious manifestation of that pattern to date." - Sergey Shykevich, Group Manager, Check Point Research
The False Flag Strategy: Why Attribution Matters
MuddyWater's use of a criminal ransomware brand to conduct state-sponsored espionage reflects an increasingly documented strategy among Iranian threat actors. By operating through the Chaos RaaS affiliate programme, the group gains several operational advantages.
"The use of a RaaS framework in this context may enable the actor to blur distinctions between state-sponsored activity and financially motivated cybercrime, thereby complicating attribution. Furthermore, the inclusion of extortion and negotiation elements could serve to focus defensive efforts on immediate impact, likely delaying the identification of underlying persistence mechanisms established via remote access tools." - Rapid7 Threat Intelligence Report, 2026
This pattern of blending state objectives with criminal tradecraft has also been documented by Ctrl-Alt-Intel, Broadcom, Check Point, and JUMPSEC, all of which have tracked MuddyWater's growing reliance on off-the-shelf tools from the cybercrime ecosystem, including CastleRAT and the Tsundere implant.
What GCC Security Teams Must Do Now
The combination of MuddyWater's Teams-based credential harvesting, the Oman government breach, and the Port of Fujairah intrusion represents a concentrated pattern of Iranian-linked cyber operations targeting GCC government, critical infrastructure, and logistics sectors.
Enterprise security teams across the region should take the following immediate steps:
- Audit Microsoft Teams external access settings. Restrict or disable the ability for external parties to initiate unsolicited screen-sharing or chat sessions with internal employees, particularly those in IT, finance, and operations roles.
- Enforce MFA with phishing-resistant methods. Standard MFA is demonstrably insufficient against this type of credential harvesting. Move towards hardware security keys or certificate-based authentication for privileged accounts.
- Audit remote management tool installations. Search environments for unauthorised instances of DWAgent, AnyDesk, and similar remote access utilities, which MuddyWater consistently uses for persistence.
- Review Teams and communication platform logs. Look for external chat initiations, screen-sharing events, and unusual credential entry patterns as indicators of early-stage compromise.
- Monitor for Stagecomp and Darkcomp indicators. The code-signing certificate attributed to "Donald Gay" and network connections to known C2 infrastructure should be added to threat hunting rulesets immediately.
For further context on Iranian-linked threat activity targeting GCC infrastructure, see Handala Hack: The Iranian-Linked Threat Actor GCC Enterprises Cannot Afford to Ignore.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.