216.73.216.6

Operation Olalampo: Inside MuddyWater's Latest Campaign

· Published 23/02/2026 10:13 · Modified 23/02/2026 10:20

Export JSON

Essential information

Published
23/02/2026 10:13
Modified
23/02/2026 10:20
Tags
2026-02-23 ai-assisted apt c2 charmpower ghostbackdoor ghostfetch http_vip mena operation olalampo post-exploitation rust backdoor telegram bot
Related entities
14 observables, 1 intrusion sets (apt), 17 techniques (mitre), 4 malware, 4 others

Description

MuddyWater has launched , targeting organizations in the region. The campaign involves new malware variants, including a called CHAR, downloaders and , and an advanced backdoor . Notably, the group is using Telegram bots for command-and-control, revealing insights into their tactics. The operation, first observed on January 26, 2026, shows tactical and technical overlaps with previous MuddyWater activities. Key discoveries include potential malware development and infrastructure reuse dating back to October 2025. The campaign aligns with ongoing geopolitical tensions and provides valuable information on the threat actor's evolving techniques.

External references