logo

Operation Olalampo: Inside MuddyWater’s Latest Campaign

ID: 1e100431-4fb7-562d-a5f0-8e5ec069ccde

STIX ID: report--1e100431-4fb7-562d-a5f0-8e5ec069ccde

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2026-02-20

Date Updated: 2026-04-28

...
...

Operation Olalampo — attributed with high confidence to the Iranian-linked APT MuddyWater — is a targeted espionage campaign (first observed 26 Jan 2026) using malicious Office documents and exploited public-facing servers to deliver multiple custom tools (GhostFetch, HTTP_VIP, GhostBackDoor, and the Rust backdoor CHAR). The operation leverages diverse C2 infrastructure (domains, Cloudflare-protected hosts, and a Telegram bot), shows evidence of infrastructure reuse and rapid tool development (including signs of AI-assisted code), includes detailed IOCs and post-exploitation activity, and provides actionable detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.