Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Analyze » Rapid7 » RAP1778084674

Incident Score: Analysis & Impact (RAP1778084674)

The details regarding individual company incidents & reports gives you full view from every side.

Rankiteo Score Impact Analysis

Rankiteo Incident Impact-17
Company Score Before Incident753 / 1000
Company Score After Incident736 / 1000
INCIDENT NUMBERRAP1778084674
Type of Cyber IncidentCyber Attack
ATTACK VECTORUnsolicited Microsoft Teams messages with interactive screen-sharing sessions
DATA EXPOSEDCredentials, sensitive organizational data
INCIDENT DATE28/02/2026
STATUSOngoing

Key Highlights From The Incident Analysis

  • Timeline of Rapid7's Cyber Attack and lateral movement inside company's environment.
  • Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
  • How Rankiteo’s incident engine converts technical details into a normalized incident score.
  • How this cyber incident impacts Rapid7 Rankiteo cyber scoring and cyber rating.
  • Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.

Full Incident Analysis Transcript

In this Rankiteo incident briefing, we review the Rapid7 breach identified under incident ID RAP1778084674.

The analysis begins with a detailed overview of Rapid7's information like the linkedin page: https://www.linkedin.com/company/rapid7, the number of followers: 213861, the industry type: Computer and Network Security and the number of employees: 3254 employees

After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 753 and after the incident was 736 with a difference of -17 which is could be a good indicator of the severity and impact of the incident.

In the next step of the video, we will analyze in more details the incident and the impact it had on Rapid7 and their customers.

On 01 January 2026, a cybersecurity incident called "Iranian APT MuddyWater Deploys Chaos Ransomware as False Flag in Espionage Campaign" came to light.

In early 2026, cybersecurity firm Rapid7 uncovered a sophisticated hybrid espionage campaign orchestrated by the Iranian Advanced Persistent Threat (APT) group MuddyWater (also known as Mango Sandstorm, Seedworm, or Static Kitten), affiliated with Iran’s Ministry of Intelligen...

The disruption is felt across the environment, affecting Domain Controllers and Endpoints with DWAgent/AnyDesk, and exposing Credentials, sensitive organizational data.

Formal response steps have not been shared publicly yet.

The case underscores how Ongoing, teams are taking away lessons such as MuddyWater leveraged trusted platforms (Microsoft Teams) for credential harvesting and MFA bypass, demonstrating the need for heightened scrutiny of interactive sessions and MFA enrollment changes, and recommending next steps like Monitor unsolicited Teams messages and screen-sharing requests, Restrict MFA device enrollment to authorized personnel only and Deploy EDR/XDR solutions to detect RATs like Game.exe.

Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.

The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.

MITRE ATT&CK® Correlation Analysis

Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Phishing: Spearphishing via Service (T1566.003) with high confidence (90%), supported by evidence indicating unsolicited Microsoft Teams messages sent to employees and Trusted Relationship (T1199) with moderate to high confidence (80%), supported by evidence indicating exploited Teams’ trusted environment to bypass security controls. Under the Execution tactic, the analysis identified User Execution: Malicious Link (T1204.001) with moderate to high confidence (80%), supported by evidence indicating interactive screen-sharing sessions instructing victims to execute commands, Command and Scripting Interpreter: PowerShell (T1059.001) with moderate to high confidence (70%), supported by evidence indicating arbitrary command execution via encoded PowerShell (Game.exe RAT), and Command and Scripting Interpreter: Windows Command Shell (T1059.003) with moderate to high confidence (70%), supported by evidence indicating executed discovery commands (ipconfig /all, whoami, net start). Under the Persistence tactic, the analysis identified External Remote Services (T1133) with high confidence (90%), supported by evidence indicating deployed DWAgent and AnyDesk for persistent remote access and Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001) with moderate confidence (60%), supported by evidence indicating rAT (Game.exe) likely established persistence via startup mechanisms. Under the Privilege Escalation tactic, the analysis identified Valid Accounts: Domain Accounts (T1078.002) with moderate to high confidence (80%), supported by evidence indicating authenticated to Domain Controllers using stolen accounts. Under the Defense Evasion tactic, the analysis identified Masquerading: Match Legitimate Name or Location (T1036.005) with high confidence (90%), supported by evidence indicating game.exe RAT disguised as legitimate Microsoft WebView2 application, Obfuscated Files or Information: Command Obfuscation (T1027.010) with moderate to high confidence (70%), supported by evidence indicating encoded PowerShell commands via Game.exe RAT, Impair Defenses: Disable or Modify Tools (T1562.001) with moderate confidence (60%), supported by evidence indicating sandbox and virtual machine detection by Game.exe, and Hijack Execution Flow: DLL Side-Loading (T1574.002) with moderate confidence (50%), supported by evidence indicating python-based process injection (pythonw.exe) used by MuddyWater. Under the Credential Access tactic, the analysis identified Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001) with moderate confidence (50%), supported by evidence indicating interactive screen-sharing sessions for credential harvesting, Input Capture: Keylogging (T1056.001) with moderate to high confidence (70%), supported by evidence indicating victims entered credentials into locally created files (credentials.txt), and Multi-Factor Authentication Request Generation (T1621) with high confidence (90%), supported by evidence indicating attackers added their devices to victims’ MFA configurations. Under the Discovery tactic, the analysis identified Account Discovery: Domain Account (T1087.002) with moderate to high confidence (80%), supported by evidence indicating executed whoami and net start commands post-compromise and System Network Configuration Discovery (T1016) with moderate to high confidence (80%), supported by evidence indicating executed ipconfig /all to gather network configuration. Under the Lateral Movement tactic, the analysis identified Remote Services: Remote Desktop Protocol (T1021.001) with moderate to high confidence (80%), supported by evidence indicating lateral movement via RDP using stolen credentials and Remote Services: SMB/Windows Admin Shares (T1021.002) with moderate confidence (60%), supported by evidence indicating likely used SMB for lateral movement to Domain Controllers. Under the Collection tactic, the analysis identified Data from Local System (T1005) with moderate to high confidence (80%), supported by evidence indicating harvested credentials and sensitive organizational data and Automated Collection (T1119) with moderate to high confidence (70%), supported by evidence indicating game.exe RAT enabled chunked file uploads and data exfiltration. Under the Command and Control tactic, the analysis identified Application Layer Protocol: Web Protocols (T1071.001) with high confidence (90%), supported by evidence indicating c2 communication via moonzonet.com (port 443), Ingress Tool Transfer (T1105) with moderate to high confidence (80%), supported by evidence indicating custom downloader (ms_upd.exe) fetched from C2 server, and Encrypted Channel: Symmetric Cryptography (T1573.001) with moderate to high confidence (70%), supported by evidence indicating aES-256-GCM encrypted RAT configuration storage. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with high confidence (90%), supported by evidence indicating data exfiltration via Game.exe RAT and C2 infrastructure and Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) with moderate confidence (60%), supported by evidence indicating c2 domains (uploadfiler.com, adm-pulse.com) suggest cloud exfiltration. Under the Impact tactic, the analysis identified Defacement: Internal Defacement (T1491.001) with moderate confidence (50%), supported by evidence indicating chaos ransomware used as false flag to mislead attribution. These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.

Initial Access
Phishing: Spearphishing via Service (90%)
Trusted Relationship (80%)
Execution
User Execution: Malicious Link (80%)
Command and Scripting Interpreter: PowerShell (70%)
Command and Scripting Interpreter: Windows Command Shell (70%)
Persistence
External Remote Services (90%)
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (60%)
Privilege Escalation
Valid Accounts: Domain Accounts (80%)
Defense Evasion
Masquerading: Match Legitimate Name or Location (90%)
Obfuscated Files or Information: Command Obfuscation (70%)
Impair Defenses: Disable or Modify Tools (60%)
Hijack Execution Flow: DLL Side-Loading (50%)
Credential Access
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay (50%)
Input Capture: Keylogging (70%)
Multi-Factor Authentication Request Generation (90%)
Discovery
Account Discovery: Domain Account (80%)
System Network Configuration Discovery (80%)
Lateral Movement
Remote Services: Remote Desktop Protocol (80%)
Remote Services: SMB/Windows Admin Shares (60%)
Collection
Data from Local System (80%)
Automated Collection (70%)
Command and Control
Application Layer Protocol: Web Protocols (90%)
Ingress Tool Transfer (80%)
Encrypted Channel: Symmetric Cryptography (70%)
Exfiltration
Exfiltration Over C2 Channel (90%)
Exfiltration Over Web Service: Exfiltration to Cloud Storage (60%)
Impact
Defacement: Internal Defacement (50%)

Sources & References