Operation Olalampo: Inside MuddyWater’s Latest Campaign
ID: 1e100431-4fb7-562d-a5f0-8e5ec069ccde
STIX ID: report--1e100431-4fb7-562d-a5f0-8e5ec069ccde
Feed Name: Group-IB Blog
Operation Olalampo — attributed with high confidence to the Iranian-linked APT MuddyWater — is a targeted espionage campaign (first observed 26 Jan 2026) using malicious Office documents and exploited public-facing servers to deliver multiple custom tools (GhostFetch, HTTP_VIP, GhostBackDoor, and the Rust backdoor CHAR). The operation leverages diverse C2 infrastructure (domains, Cloudflare-protected hosts, and a Telegram bot), shows evidence of infrastructure reuse and rapid tool development (including signs of AI-assisted code), includes detailed IOCs and post-exploitation activity, and provides actionable detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
