MuddyWater Operation Olalampo — Iran MOIS-Nexus APT Deploys New Malware Variants with Telegram Bot C2 Targeting Middle Eastern Governments and Critical Infrastructure

MuddyWater Operation Olalampo (TL-2026-0158), also tracked as Operation Olalampo, is a high-severity advanced persistent threat campaign, first published 2026-02-28. It is attributed to MuddyWater (Iran) with high confidence, affects Multiple Government IT Infrastructure, references 3 CVEs (CVE-2017-0199, CVE-2020-0688, CVE-2020-1472), maps to 29 MITRE ATT&CK techniques (T1003.001, T1027.010, T1036.005), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0158

Threat ID
TL-2026-0158
Also known as
Operation Olalampo
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-02-28
Last reviewed
2026-02-28
Attribution
MuddyWater
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
government, telecommunications, energy, defense, oil-and-gas
Target regions
Middle East, Central Asia, South Asia, Africa, Europe, North America
Detection rules
9
Indicators of compromise
20

Malware and tooling in MuddyWater Operation Olalampo

Malware and tooling: GRAMDOOR, ConnectWise - S0591, Lazagne, Mimikatz, ProcDump, RemoteUtilities - S0592, SimpleHelp

Group-IB has disclosed Operation Olalampo, a cyber espionage campaign by MuddyWater (Mercury/Mango Sandstorm/Static Kitten/TEMP.Zagros/Seedworm/TA450/Earth Vetala), an Iranian APT group subordinate to the Ministry of Intelligence and Security (MOIS). The campaign deploys new malware variants leveraging Telegram Bot API for command-and-control, evolving the group's Small Sieve tradecraft with enhanced capabilities targeting Middle Eastern government and critical infrastructure organizations.

How MuddyWater Operation Olalampo works

Group-IB published research on February 20, 2026 disclosing Operation Olalampo, a new offensive campaign by MuddyWater — one of the most prolific Iranian APT groups, confirmed by the FBI, CISA, U.S. Cyber Command CNMF, and the UK NCSC as a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Active since approximately 2018, MuddyWater has conducted broad cyber espionage campaigns in support of MOIS intelligence collection objectives across Asia, Africa, Europe, and North America.

Operation Olalampo represents an evolution of MuddyWater's tooling, deploying new malware variants that leverage Telegram Bot API as primary command-and-control infrastructure. This C2 channel is not entirely novel for the group — their Small Sieve backdoor (a Python-based implant documented in joint CISA/NCSC-UK advisory AA22-055A) already used Telegram Bot API over HTTPS with hex byte-swapping and obfuscated Base64 encoding for beacons and tasking. However, Operation Olalampo introduces updated variants with enhanced capabilities, likely addressing operational security deficiencies identified in the original Small Sieve exposure.

MuddyWater's attack chain historically follows a consistent pattern: spearphishing emails with malicious attachments (Excel macros, PDF droppers, or document files) or links to file-sharing services (OneHub, Sync, TeraBox) deliver initial payloads. The group is known for heavy reliance on PowerShell-based tooling (POWERSTATS backdoor), living-off-the-land techniques using system binaries (CMSTP.exe, mshta.exe, rundll32.exe), and DLL side-loading for defense evasion. Their malware suite includes PowGoop (DLL loader + PowerShell downloader disguised as Google Update), Small Sieve (Telegram Bot C2), Canopy/Starwhale (WSF-based collector), Mori (DNS tunneling backdoor), and POWERSTATS (PowerShell persistence backdoor).

The group maintains persistence through Registry Run keys, scheduled tasks, Office template macros, and DLL side-loading. For credential access, they deploy Mimikatz, LaZagne, procdump64.exe, and Browser64. Lateral movement leverages legitimate remote access tools including ConnectWise (ScreenConnect), RemoteUtilities, and SimpleHelp. Data exfiltration occurs over C2 channels using Base64 and XOR encoding.

MuddyWater has historically exploited CVE-2017-0199 (Office), CVE-2020-0688 (Exchange memory corruption), and CVE-2020-1472 (Netlogon/ZeroLogon) for initial access and privilege escalation. Their targeting focuses on government agencies, telecommunications providers, defense contractors, energy sector organizations, and oil and gas companies — particularly in the Middle East and Central/South Asia.

This is the first Iran-nexus APT threat on the Threadlinqs Intelligence Platform, adding a critical new nation-state dimension to platform coverage alongside existing China (4 threats), North Korea (5 threats), Russia, and Belarus clusters.

MITRE ATT&CK techniques used in TL-2026-0158

credential-access

T1003.001 LSASS Memory; T1555.003 Credentials from Web Browsers

defense-evasion

T1027.010 Command Obfuscation; T1036.005 Match Legitimate Resource Name or Location; T1218.005 Mshta; T1480 Execution Guardrails

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1047 Windows Management Instrumentation; T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.005 Visual Basic; T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File

discovery

T1057 Process Discovery; T1082 System Information Discovery

command-and-control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1219 Remote Access Tools

persistence

T1137.001 Office Template Macros; T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL

privilege-escalation

T1548.002 Bypass User Account Control

initial-access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

resource-development

T1583.006 Web Services; T1588.002 Tool

Affected products and versions in MuddyWater Operation Olalampo

  • Multiple — Government IT Infrastructure
    Vulnerable versions: Middle Eastern government networks, diplomatic agencies
  • Multiple — Telecommunications Infrastructure
    Vulnerable versions: Telecom providers in Middle East, Central Asia, South Asia
  • Multiple — Energy Sector / Oil & Gas SCADA
    Vulnerable versions: Energy and O&G organizations in target regions
  • Multiple — Defense Contractors
    Vulnerable versions: Defense sector organizations in target regions

Remediation for MuddyWater Operation Olalampo

Patches

  • CVE-2017-0199 — Microsoft Office OLE vulnerability
  • CVE-2020-0688 — Microsoft Exchange Server memory corruption
  • CVE-2020-1472 — Microsoft Netlogon elevation of privilege (ZeroLogon)

Immediate actions

  • Search for IOCs: Telegram Bot API beacons, PowGoop DLL side-loading artifacts, POWERSTATS PowerShell scripts
  • Block known MuddyWater C2 IP 95.181.161.49 and associated infrastructure at network perimeter
  • Monitor for Telegram Bot API traffic from corporate endpoints — legitimate Telegram use should be baselined
  • Audit Registry Run keys for suspicious entries (e.g., SystemTextEncoding under HKCU\Software\Microsoft\Windows\CurrentVersion\Run)
  • Check for PowGoop artifacts: Goopdate.dll, goopdate.dat, config.txt in GoogleUpdate paths
  • Scan for Small Sieve: gram_app.exe NSIS installer, index.exe Python backdoor with Telegram C2

Workarounds

  • Disable macros in Office documents from external sources
  • Block CMSTP.exe and mshta.exe via application control policies where not required
  • Restrict PowerShell execution to signed scripts only via execution policy
  • Monitor and alert on outbound connections to Telegram API endpoints (api.telegram.org)

Longer-term hardening

  • Implement application whitelisting to prevent execution of unauthorized PowerShell scripts and LOLBIN abuse
  • Deploy EDR with behavioral detection for CMSTP.exe, mshta.exe, and rundll32.exe misuse patterns
  • Patch CVE-2020-0688 (Exchange) and CVE-2020-1472 (Netlogon) if not already applied
  • Implement PowerShell constrained language mode and script block logging
  • Monitor for DLL side-loading: legitimate executables loading unsigned DLLs from non-standard paths
  • Deploy network segmentation to limit lateral movement via remote access tools
  • Implement MFA on all external-facing services and VPN access

CVEs associated with MuddyWater Operation Olalampo

CVE-2017-0199, CVE-2020-0688, CVE-2020-1472

Weaknesses (CWE) in MuddyWater Operation Olalampo

CWE-506, CWE-912, CWE-94

Timeline of MuddyWater Operation Olalampo

  • Palo Alto Unit42 publishes first public documentation of MuddyWater targeting Middle Eastern organizations with spearphishing campaigns. Source: Unit42
  • FireEye documents MuddyWater TTP evolution including CMSTP.exe proxy execution, POWERSTATS payload, and updated spearphishing techniques. Source: FireEye
  • Kaspersky publishes comprehensive MuddyWater technical analysis covering malware capabilities, persistence mechanisms, and VBA/PowerShell toolchain. Source: Kaspersky SecureList
  • U.S. Cyber Command confirms MuddyWater as subordinate element of Iran MOIS, publishes malware samples to VirusTotal. Source: USCYBERCOM
  • FBI, CISA, CNMF, and NCSC-UK publish joint advisory AA22-055A documenting MuddyWater's full malware suite (PowGoop, Small Sieve, Canopy/Starwhale, Mori, POWERSTATS) and Telegram Bot C2 via Small Sieve. Source: CISA
  • Group-IB publishes analysis of MuddyWater C2 infrastructure including ConnectWise, RemoteUtilities, and SimpleHelp abuse patterns. Source: Group-IB
  • Group-IB discloses Operation Olalampo — new MuddyWater campaign with updated malware variants leveraging Telegram Bot C2. Targets Middle Eastern governments and critical infrastructure. Source: Group-IB Blog
  • SentinelOne Week 9 summary covers MuddyWater Operation Olalampo, confirming novel malware suite and sustained MENA campaign. Notes possible AI-assisted development of CHAR backdoor.
  • SentinelOne publishes Iranian Cyber Activity Outlook following U.S./Israeli strikes on Iranian targets. Assesses Iranian state-aligned cyber activity (including MuddyWater) likely to intensify. High-confidence targeting expected against U.S./Israel/allied government, critical infrastructure, defense, financial, academic, and media sectors.
  • Threat published to Threadlinqs Intelligence Platform as TL-2026-0158. First Iran-nexus APT on platform.
  • As of 2026-05-29, Operation Olalampo remains ACTIVE: Group-IB-disclosed MuddyWater (MOIS/Seedworm) campaign first seen Jan 26 2026 deploying GhostFetch/CHAR/Telegram-bot C2, with the actor continuing parallel operations into March 2026 (Dindoor vs US orgs, RustyWater vs Israel). Abused CVEs (2017-0199, 2020-0688, 2020-1472) are patched but still actively exploited; actor is operational, not disrupted.

Sources cited for MuddyWater Operation Olalampo

Threats related to MuddyWater Operation Olalampo

Detection coverage for TL-2026-0158

As of 2026-02-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0158 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats