By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
Tech News

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

By Viral Trending Content 5 Min Read
Share
SHARE

Ravie LakshmananFeb 23, 2026Threat Intelligence / Artificial Intelligence

The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo.

The activity, first observed on January 26, 2026, has resulted in the deployment of new malware families that share overlapping samples previously identified as used by the threat actor, according to a report published by Group-IB. These include downloaders like GhostFetch and HTTP_VIP, along with a Rust backdoor called CHAR and an advanced implant codenamed GhostBackDoor that’s dropped by GhostFetch.

“These attacks follow similar patterns and align with the killchains previously observed in MuddyWater attacks; starting with a phishing email with a Microsoft Office document attached to it that contains malicious macro code that decodes the embedded payload and drops it on the system and executes it, providing the adversary with remote control of the system,” the company said.

One such attack chain employing a malicious Microsoft Excel document prompts users to enable macros in order to activate the infection and ultimately drop CHAR. Another variant of the same attack has been found to lead to the deployment of the GhostFetch downloader, which then downloads GhostBackDoor.

A third version of the attack leverages themes such as flight tickets and reports, in contrast to using lures mimicking an energy and marine services company in the Middle East, to distribute the HTTP_VIP downloader that subsequently deploys the AnyDesk remote desktop software.

A brief description of the four tools is as follows –

  • GhostFetch, a first-stage downloader that profiles the system, validates mouse movements and checks screen resolution, checks for the presence of debuggers, virtual machine artifacts, and antivirus software, and fetches and executes secondary payloads directly in memory.
  • GhostBackDoor, a second-stage backdoor delivered by GhostFetch that supports an interactive shell, file read/write, and re-run GhostFetch.
  • HTTP_VIP, a native downloader that conducts system reconnaissance, connects to an external server (“codefusiontech[.]org”) to authenticate and deploy AnyDesk from the C2 server. A new variant of the malware also adds the ability to retrieve victim information and retrieve instructions to start an interactive shell, download/upload files, capture clipboard contents, and update the sleep/beaconing interval.
  • CHAR, a Rust backdoor that’s controlled by a Telegram bot (whose first name is “Olalampo” and username is “stager_51_bot”) to change directory and execute a cmd.exe or PowerShell command.

The PowerShell command is designed to execute a SOCKS5 reverse proxy or another backdoor named Kalim, upload data stolen from web browsers, and run unknown executables referred to as “sh.exe” and “gshdoc_release_X64_GUI.exe.”

Group-IB’s analysis of CHAR’s source code has revealed signs of artificial intelligence (AI)-assisted development owing to the presence of emojis in debug strings, a finding that’s consistent with Google’s revelations last year that the threat actor is experimenting with generative AI tools to support the development of custom malware to support file transfer and remote execution.

Another notable aspect is that CHAR shares a similar structure and development environment as the Rust-based malware BlackBeard (aka Archer RAT and RUSTRIC), which was flagged by CloudSEK and Seqrite Labs as put to use by the threat actor to target various entities in the Middle East.

MuddyWater has also been observed exploiting recently disclosed vulnerabilities on public-facing servers as a way to obtain initial access to target networks.

“The MuddyWater APT group remains an active threat within the META region, with this operation primarily targeting organizations in the MENA region,” Group-IB concluded. “The group’s continued adoption of AI technology, combined with continued development of custom malware and tooling and diversified command-and-control (C2) infrastructures, underscores their dedication and intent to expand their operations.”

You Might Also Like

U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage

Meta and Google face multi-million dollar fines for addictive apps

Best Noise-Canceling Earbuds: Bose, Sony, Apple, and More

Plans for new Irish supercomputer CASPIR moves to next stage

5 new WhatsApp Features you Should Start Using

TAGGED: artificial intelligence, Backdoor, Cyber Security, Cybersecurity, Internet, Iran, Malware, phishing, Remote Access Software, Threat Intelligence, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article How does the EU plan to step up competitiveness? Ask the Euronews AI chatbot
Next Article Europe’s wealth divide mapped: Where are adults richest and poorest?
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Pokémon FireRed and LeafGreen were primarily designed for girls and the elderly
Gaming News
Cyprus: War-related tourism concerns and climate change efforts
Travel
U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage
Tech News
Meta and Google face multi-million dollar fines for addictive apps
Tech News
Markets rally, oil prices fall as Trump signals Iran talks
Business
ICE agents called in to help ease airport security lines may not be leaving anytime soon, even after Trump ordered pay for TSA officers
Business
Kalshi legal woes grow with Washington state gambling suit
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?