MuddyWater’s Operation Olalampo Targets MENA with AI Malware

Iranian hackers launch AI-assisted malware in new Middle East cyber-espionage campaign.

  • The Iranian state-sponsored hacking group MuddyWater has launched a new campaign called Operation Olalampo, deploying multiple new malware families.
  • The group utilized AI-assisted development tools to create a Rust-based backdoor and targeted organizations in the Middle East and North Africa via malicious email attachments.
  • Security researchers at Group-IB found the malware shares code with prior tools, indicating continuous evolution of the threat actor’s capabilities.

The Iranian cyber-espionage group MuddyWater has targeted entities across the Middle East and North Africa since late January 2026 with a sophisticated new malware suite, according to a report published by Group-IB. This campaign, codenamed Operation Olalampo, involves phishing emails with malicious documents that deploy a range of custom tools.

- Advertisement -

Consequently, the attack chains ultimately drop downloaders like GhostFetch and HTTP_VIP, which fetch advanced backdoors. One notable implant is a Rust-based backdoor named CHAR, which is controlled via a Telegram bot for remote command execution.

Meanwhile, a separate downloader variant leads to GhostBackDoor, granting attackers an interactive shell and file control. Analysts found that CHAR’s source code contains emojis in debug strings, suggesting “signs of artificial intelligence (AI)-assisted development”.

This finding aligns with previous observations that the group experiments with generative AI for malware creation. Furthermore, CHAR shares structural similarities with another Rust malware, BlackBeard, previously used by the same actor.

The group has also been observed exploiting recent vulnerabilities on public-facing servers for initial access. Group-IB concluded that the operation highlights MuddyWater’s dedication to expanding its technical capabilities and regional focus.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Ethereum Flirts with $1,500 Support Amid Selling Pressure

Ethereum has entered the breakdown phase of its prevailing bearish continuation pattern.ETH price may...

CZ Sees Crypto Capital Moving to RWAs and Prediction Markets

Former Binance CEO Changpeng "CZ" Zhao predicts the next major focus for crypto capital...

72% Chance Bitcoin Falls Below $55K By 2026

Prediction markets on Polymarket show a 72% chance of Bitcoin falling below $55,000 before...

AI Agent ‘Accidentally’ Sends $441K in Crypto Beggar Scam

An AI agent named Lobstar Wilde accidentally sent over $441,780 worth of tokens to...

Bitcoin Crash Sparks Extreme Fear, $458M Liquidated

Bitcoin plunged over 4% to $64,300, triggering $458 million in trader liquidations.The Crypto Fear...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!