logo

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

ID: 7f3c9453-cb2e-5615-bef3-cdbe30d0ccc7

STIX ID: report--7f3c9453-cb2e-5615-bef3-cdbe30d0ccc7

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Operation Olalampo is an active campaign attributed to the Iranian APT MuddyWater targeting organizations across the MENA region; the actor uses phishing (malicious Office macros) and public-facing vulnerability exploits to deliver downloaders and backdoors (GhostFetch, GhostBackDoor, HTTP_VIP, CHAR), enabling remote control, file transfer, data theft and AnyDesk deployment, with indicators of AI-assisted malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.