MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
ID: 7f3c9453-cb2e-5615-bef3-cdbe30d0ccc7
STIX ID: report--7f3c9453-cb2e-5615-bef3-cdbe30d0ccc7
Feed Name: The Hacker News
Threat Score
Operation Olalampo is an active campaign attributed to the Iranian APT MuddyWater targeting organizations across the MENA region; the actor uses phishing (malicious Office macros) and public-facing vulnerability exploits to deliver downloaders and backdoors (GhostFetch, GhostBackDoor, HTTP_VIP, CHAR), enabling remote control, file transfer, data theft and AnyDesk deployment, with indicators of AI-assisted malware development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
