4 min read

The Art of Looking Innocent: Iran's Dual-Track Tradecraft Evolution- 198

The Art of Looking Innocent: Iran's Dual-Track Tradecraft Evolution- 198

June 23, 2026

Iran's most effective cyber operations in 2026 do not announce themselves. One looked like routine software traffic — signed binaries, consumer cloud services, a 90-second beacon nobody was watching for. The other looked like a ransomware attack — extortion emails, a leak site listing, a ransom negotiation. Neither was what it appeared to be. Read together, they describe a single strategic objective: make attribution as expensive as possible, by ensuring that the first answer defenders reach is always the wrong one.

Two Iranian cyber operations disclosed within weeks of each other in spring 2026 appear, on the surface, to be unrelated: one a disciplined, technically precise espionage campaign spanning nine countries across four continents, the other a social engineering intrusion that dressed itself in the costume of a ransomware gang and confused defenders into running the wrong incident response playbook. Read together, they describe not two operations but one strategy — the systematic engineering of deniability through misdirection, executed simultaneously at the technical and the organisational level.

The Seedworm campaign, documented by Symantec's Threat Hunter Team, ran through the first quarter of 2026 and affected at least nine organisations across industrial manufacturing, financial services, public sector, and education — including a week-long intrusion into the network of a major South Korean electronics manufacturer, a significant geographic departure for a group whose traditional hunting ground is the Middle East and South Asia. The breadth of targeting reflects broadened intelligence requirements: intellectual property from high-tech manufacturing, government data, and downstream access through professional services providers all represent material value to Tehran's intelligence apparatus under conditions of sustained regional tension and pressure over Iran's nuclear programme. The specific victim profile — organisations that hold what the threat actor wants, distributed across jurisdictions that complicate law enforcement coordination — is itself a deliberate operational choice.

What distinguishes this campaign technically is not any single novel technique but the combination and discipline with which established techniques were assembled. The group used DLL sideloading throughout, but the choice of signed binaries is analytically telling: one pair involved fmapp.exe, a legitimate Fortemedia audio utility whose abuse in prior Seedworm campaigns is documented, while the second pair used sentinelmemoryscanner.exe, a signed component of the SentinelOne endpoint security product. Abusing a security vendor's own binary is a deliberate triage-confusion move — a process launched from a SentinelOne executable is precisely the kind of process a defender's first instinct may exempt from scrutiny. PowerShell remained central to the operation, but where earlier Seedworm activity drove it directly, in this campaign Node.js served as the orchestration layer, making PowerShell a child of node.exe rather than a standalone process, and shifting the observable telemetry away from the indicators that hunt-rules and detection logic are calibrated to catch. Exfiltration occurred through sendit.sh, a public consumer file-transfer service — not bespoke attacker infrastructure, but traffic that blends with the ordinary background noise of cloud service usage. The 90-second beaconing cadence, the repeated relaunching of sideloaded binaries to maintain tunnel availability, the redundant credential-theft toolkit deployed in sequence in case any individual tool was blocked — these are the operational signatures of a group that has moved from competent to disciplined, that has absorbed the lesson that persistence and patience matter more than sophistication on any single axis.

The MuddyWater/Chaos operation, documented by Rapid7, works at a different level. The entry was social engineering through Microsoft Teams — attackers posing as internal contacts, establishing one-on-one conversations, persuading employees into screen-sharing sessions through which VPN configuration files were accessed and credentials were typed into locally saved text files at the attacker's instruction. AnyDesk and DWAgent were installed for persistent remote access. Stolen data was then exfiltrated. So far, an espionage operation. What follows is the deception layer: the attackers sent extortion emails to employees in the voice of the Chaos ransomware group, directed victims to the Chaos leak site where the organisation had been listed, and initiated ransom negotiations. No encryption was ever deployed. No ransomware had been executed. The entire ransomware presentation — the extortion demand, the negotiation, the data-leak threat — was a false flag designed to route the victim's incident response toward the financial-crime playbook, toward ransom-payment calculations and leak-site monitoring, and away from the persistent access tools and the intelligence collection that constituted the actual operation. The attackers' goal was not a ransom payment. It was dwell time. The ransomware aesthetic was the mechanism for buying it.

The MuddyWater false flag diagram — a simple two-layer view showing what the attack appeared to be (Chaos ransomware operation) versus what it actually was (espionage with dwell-time objective), making the deception architecture visible

Rapid7's attribution of the operation to MuddyWater rests on technical overlap — specific code-signing certificates and command-and-control infrastructure previously associated with the group — alongside the contextual consistency of targeting. This is not the first time MuddyWater has used criminal branding as operational cover: the group was previously linked to the Qilin ransomware ecosystem following an attack on an Israeli organisation, and Iran's MOIS actors have been documented partnering with affiliates of the NoEscape, Ransomhouse, and AlphV ransomware operations — sometimes taking a percentage of ransom payments, sometimes simply borrowing the aesthetic. The pattern, as Rapid7's researchers noted, reflects a strategic calculation: by blurring the boundary between state espionage and financially motivated cybercrime, Iranian operators impose an attribution burden on defenders that buys operational continuity.

These two tracks — technical legitimacy abuse and strategic criminal mimicry — serve the same overarching purpose. Making Iranian state operations look like ordinary traffic through the use of signed binaries and consumer cloud services is one way to avoid detection; making them look like someone else's criminal operation is another. The compound effect, operating simultaneously, is an attribution environment in which the defender's first and most urgent question — "what is this and who is doing it?" — has been deliberately made harder to answer. Against that background, the Wipro advisory's observation that the loudest cyber activity during geopolitical stress is rarely the most dangerous reads as an operational intelligence warning as much as a board-level one: what Iran's hacktivists and proxies are visibly doing in the hacktivist noise layer is not where the collection is happening.