Tag: MENA Organizations

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
News

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

As part of a new effort codenamed Operation Olalampo, the Iranian hacker collective known as MuddyWater (also known as Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted a number of organizations and individuals mostly situated around the Middle East and North Africa (MENA) region. According to a Group-IB assessment, the action, which was initially noticed on January 26, 2026, has led to the deployment of new malware families that share overlapping samples that were previously detected as being used by the threat actor. CHAR is a Rust backdoor, GhostFetch drops a complex implant nicknamed GhostBackDoor, and downloaders like GhostFetch and HTTP_VIP are among them. According to the company, these attacks start with a phishing email with a Microsoft Office document attached th...