MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

spsingh
By
spsingh
5 Min Read

Ravie LakshmananFeb 23, 2026Threat Intelligence / Synthetic Intelligence

The Iranian hacking group generally known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has focused a number of organizations and people primarily situated throughout the Center East and North Africa (MENA) area as a part of a brand new marketing campaign codenamed Operation Olalampo.

The exercise, first noticed on January 26, 2026, has resulted within the deployment of recent malware households that share overlapping samples beforehand recognized as utilized by the risk actor, in keeping with a report printed by Group-IB. These embody downloaders like GhostFetch and HTTP_VIP, together with a Rust backdoor referred to as CHAR and a sophisticated implant codenamed GhostBackDoor that is dropped by GhostFetch.

One such assault chain using a malicious Microsoft Excel doc prompts customers to allow macros as a way to activate the an infection and finally drop CHAR. One other variant of the identical assault has been discovered to result in the deployment of the GhostFetch downloader, which then downloads GhostBackDoor.

A 3rd model of the assault leverages themes reminiscent of flight tickets and reviews, in distinction to utilizing lures mimicking an power and marine companies firm within the Center East, to distribute the HTTP_VIP downloader that subsequently deploys the AnyDesk distant desktop software program.

A quick description of the 4 instruments is as follows –

GhostFetch, a first-stage downloader that profiles the system, validates mouse actions and checks display decision, checks for the presence of debuggers, digital machine artifacts, and antivirus software program, and fetches and executes secondary payloads immediately in reminiscence.
GhostBackDoor, a second-stage backdoor delivered by GhostFetch that helps an interactive shell, file learn/write, and re-run GhostFetch.
HTTP_VIP, a local downloader that conducts system reconnaissance, connects to an exterior server (“codefusiontech[.]org”) to authenticate and deploy AnyDesk from the C2 server. A brand new variant of the malware additionally provides the power to retrieve sufferer data and retrieve directions to start out an interactive shell, obtain/add information, seize clipboard contents, and replace the sleep/beaconing interval.
CHAR, a Rust backdoor that is managed by a Telegram bot (whose first identify is “Olalampo” and username is “stager_51_bot”) to vary listing and execute a cmd.exe or PowerShell command.

The PowerShell command is designed to execute a SOCKS5 reverse proxy or one other backdoor named Kalim, add knowledge stolen from internet browsers, and run unknown executables known as “sh.exe” and “gshdoc_release_X64_GUI.exe.”

Group-IB’s evaluation of CHAR’s supply code has revealed indicators of synthetic intelligence (AI)-assisted improvement owing to the presence of emojis in debug strings, a discovering that is per Google’s revelations final 12 months that the risk actor is experimenting with generative AI instruments to facilitate the event of customized malware to assist file switch and distant execution.

One other notable side is that CHAR shares an identical construction and improvement setting because the Rust-based malware BlackBeard (aka Archer RAT and RUSTRIC), which was flagged by CloudSEK and Seqrite Labs as put to make use of by the risk actor to focus on numerous entities within the Center East.

MuddyWater has additionally been noticed exploiting just lately disclosed vulnerabilities on public-facing servers as a strategy to acquire preliminary entry to focus on networks.

“The MuddyWater APT group remains an active threat within the META [Middle East, Turkey, and Africa] region, with this operation primarily targeting organizations in the MENA region,” Group-IB concluded. “The group’s continued adoption of AI technology, combined with continued development of custom malware and tooling and diversified command-and-control (C2) infrastructures, underscores their dedication and intent to expand their operations.”

Website |  + posts
author avatar
spsingh
Share This Article