MuddyWater Operation Olalampo — Iran MOIS-Nexus APT Deploys New Malware Variants with Telegram Bot C2 Targeting Middle Eastern Governments and Critical Infrastructure — Threadlinqs Intelligence
As of 2026-05-30, MuddyWater Operation Olalampo — Iran MOIS-Nexus APT Deploys New Malware Variants with Telegram Bot C2 Targeting Middle Eastern Governments and Critical Infrastructure is a high-severity apt threat attributed to MuddyWater (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0158 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: MuddyWater · Iran · ESPIONAGE
Group-IB has disclosed Operation Olalampo, a cyber espionage campaign by MuddyWater (Mercury/Mango Sandstorm/Static Kitten/TEMP.Zagros/Seedworm/TA450/Earth Vetala), an Iranian APT group subordinate to
Group-IB published research on February 20, 2026 disclosing Operation Olalampo, a new offensive campaign by MuddyWater — one of the most prolific Iranian APT groups, confirmed by the FBI, CISA, U.S. Cyber Command CNMF, and the UK NCSC as a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Active since approximately 2018, MuddyWater has conducted broad cyber espionage campaigns in support of MOIS intelligence collection objectives across Asia, Africa, Europe, and North America.
Operation Olalampo represents an evolution of MuddyWater's tooling, deploying new malware variants that leverage Telegram Bot API as primary command-and-control infrastructure. This C2 channel is not entirely novel for the group — their Small Sieve backdoor (a Python-based implant documented in joint CISA/NCSC-UK advisory AA22-055A) already used Telegram Bot API over HTTPS with hex byte-swapping and obfuscated Base64 encoding for beacons and tasking. However, Operation Olalampo introduces updated variants with enhanced capabilities, likely addressing operational security deficiencies identified in the original Small Sieve exposure.
MuddyWater's attack chain historically follows a consistent pattern: spearphishing emails with malicious attachments (Excel macros, PDF droppers, or document files) or links to file-sharing services (OneHub, Sync, TeraBox) deliver initial payloads. The group is known for heavy reliance on PowerShell-based tooling (POWERSTATS backdoor), living-off-the-land techniques using system binaries (CMSTP.exe, mshta.exe, rundll32.exe), and DLL side-loading for defense evasion. Their malware suite includes PowGoop (DLL loader + PowerShell downloader disguised as Google Update), Small Sieve (Telegram Bot C2), Canopy/Starwhale (WSF-based collector), Mori (DNS tunneling backdoor), and POWERSTATS (PowerShell persistence backdoor).
The group maintains persistence through Registry Run keys, scheduled tasks, Office template macros, and DLL side-loading. For credential access, they deploy Mimikatz, LaZagne, procdump64.exe, and Browser64. Lateral movement leverages legitimate remote access tools including ConnectWise (ScreenConnect), RemoteUtilities, and SimpleHelp. Data exfiltration occurs over C2 channels using Base64 and XOR encoding.
MuddyWater has historically exploited CVE-2017-0199 (Office), CVE-2020-0688 (Exchange memory corruption), and CVE-2020-1472 (Netlogon/ZeroLogon) for initial access and privilege escalation. Their targeting focuses on government agencies, telecommunications providers, defense contractors, energy sector organizations, and oil and gas companies — particularly in the Middle East and Central/South Asia.
This is the first Iran-nexus APT threat on the Threadlinqs Intelligence Platform, adding a critical new nation-state dimension to platform coverage alongside existing China (4 threats), North Korea (5 threats), Russia, and Belarus clusters.
Weaknesses (CWE)
CWE-506, CWE-912, CWE-94
Target sectors: government, telecommunications, energy, defense, oil-and-gas
Target regions: Middle East, Central Asia, South Asia, Africa, Europe, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2017-0199, CVE-2020-0688, CVE-2020-1472, T1566.001, T1566.002, T1059.001, T1059.005, T1059.006, T1059.007, T1204.002, T1047, T1547.001, T1053.005