logo

Iran's MuddyWater Targets Orgs With Fresh Malware as Tensions Mount

ID: 9dd10f0b-6b89-50c6-9ac0-a596a82e9371

STIX ID: report--9dd10f0b-6b89-50c6-9ac0-a596a82e9371

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-02-23

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Group-IB describes Operation Olalampo, an active MuddyWater (Iran-linked) campaign targeting organizations across the Middle East and Africa using spear-phishing and some public-server exploits to deliver several new custom malware families (including a Rust-based Char backdoor using a Telegram bot C2, GhostFetch/GhostBackDoor, and the HTTP_VIP downloader that deploys RMM). The report notes AI-assisted development artifacts, infrastructure reuse, and provides IoCs, YARA and EDR guidance and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.