Dossier
Mango Sandstorm
Coverage of Mango Sandstorm in the Nexus archive.
- MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
MuddyWater, an Iranian state-sponsored hacking group, has been attributed to a false flag ransomware attack that leverages social engineering techniques via Microsoft Teams. The attack was observed by Rapid7 in early 2026 and initiates the infection sequence. MuddyWater is also known as Mango Sandstorm, Seedworm, and Static Kitten.