CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware Suite with Telegram Bot C2
CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP (TL-2026-0160), also tracked as "[\"CHAR Backdoor\", is a critical-severity advanced persistent threat campaign, first published 2026-03-01. It is attributed to MuddyWater (Iran) with high confidence, maps to 46 MITRE ATT&CK techniques (T1003.001, T1003.004, T1005), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-0160
- Threat ID
- TL-2026-0160
- Also known as
- "[\"CHAR Backdoor\", \"GhostFetch\", \"GhostBackDoor\", \"HTTP_VIP\"]"
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-03-01
- Last reviewed
- 2026-03-01
- Attribution
- MuddyWater
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP
Malware and tooling: CHAR, GhostBackDoor, GhostFetch, HTTP_VIP, Lazagne, Mimikatz
The UK NCSC weekly threat report (March 1, 2026) identifies a new MuddyWater malware suite comprising CHAR (Rust-based backdoor), GhostFetch and HTTP_VIP (downloaders), and GhostBackDoor (advanced backdoor). Infrastructure analysis reveals overlap with historic MuddyWater (Iran/MOIS-linked) operations, featuring AI-assisted code generation, heavy obfuscation, and Telegram Bot API for C2 — evolving from the Small Sieve Python backdoor documented in CISA/FBI/CNMF/NCSC-UK joint advisory AA22-055A.
How CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP works
CHAR represents a significant evolution in MuddyWater's malware arsenal — a Rust-based backdoor marking the group's first known use of the Rust programming language for implant development. This language choice provides memory safety guarantees that complicate reverse engineering and exploitation of the implant itself, while also generating binaries that are harder for traditional signature-based detection to fingerprint due to Rust's unique compilation artifacts and standard library linking patterns. The campaign deploys a four-component malware suite: 1. **CHAR (Rust Backdoor)**: The primary implant, compiled in Rust with heavy string obfuscation and anti-analysis techniques. CHAR provides full remote access capabilities including command execution, file operations, process manipulation, and credential harvesting. The Rust implementation suggests deliberate investment in tooling modernization — MuddyWater historically relied on PowerShell (POWERSTATS), Python (Small Sieve, Out1), and .NET payloads. 2. **GhostFetch (Downloader)**: A lightweight first-stage downloader responsible for initial beacon and payload retrieval. GhostFetch establishes initial C2 contact and downloads the CHAR implant or other second-stage payloads. Uses HTTP/HTTPS with custom User-Agent strings and encoded beacon parameters. 3. **HTTP_VIP (Downloader)**: An alternative first-stage downloader with HTTP-based C2, featuring anti-sandbox checks (timing-based execution delays, environment fingerprinting) before payload delivery. HTTP_VIP checks for virtualization indicators, debugger presence, and sandbox artifacts before proceeding with download operations. 4. **GhostBackDoor (Advanced Backdoor)**: A secondary backdoor providing redundant access with additional capabilities including screenshot capture, keylogging, and browser credential theft. GhostBackDoor serves as a persistence mechanism if the primary CHAR implant is detected and removed. **Telegram Bot C2 Channel**: The campaign uses Telegram Bot API as a C2 channel — a direct evolution from MuddyWater's Small Sieve backdoor (documented in NCSC-UK MAR and CISA AA22-055A). Small Sieve used Telegram Bot API over HTTPS with hex byte swapping and obfuscated Base64 encoding. The new suite builds on this approach with improved encoding schemes and operational security. Telegram's legitimate traffic patterns make network-level detection challenging. **AI-Assisted Development Indicators**: Code analysis reveals patterns consistent with AI-assisted development: uniform code commenting styles, consistent error handling patterns across all four components, and code generation artifacts suggesting automated mutation or generation. This represents a concerning trend in APT tooling — AI acceleration of malware development cycles. **Infrastructure Overlap with MuddyWater**: Network infrastructure analysis shows overlap with historically attributed MuddyWater C2 servers, including shared IP ranges, hosting providers, and domain registration patterns. MuddyWater (also known as Mango Sandstorm, MERCURY, Static Kitten, Seedworm, Earth Vetala, TEMP.Zagros) is a subordinate element of Iran's Ministry of Intelligence and Security (MOIS), active since approximately 2017, conducting cyber espionage targeting government, telecommunications, defense, oil and gas sectors across Asia, Africa, Europe, and North America. **Kill Chain**: Initial access via spearphishing attachments (malicious Office documents with VBA macros or PDF files with embedded links) delivers GhostFetch or HTTP_VIP downloaders. These retrieve and execute the CHAR Rust backdoor, which establishes persistent C2 via Telegram Bot API. GhostBackDoor is deployed as a redundancy measure. Post-compromise activities include credential harvesting (LaZagne, Mimikatz patterns), lateral movement via stolen credentials, and data exfiltration over the C2 channel. **Relationship to TL-2026-0158**: This represents a continuation of MuddyWater operations documented in TL-2026-0158 (Operation Olalampo), but with significantly modernized tooling. The shift from PowerShell/Python to Rust for the primary implant, combined with AI-assisted development, indicates an ongoing investment in capability enhancement by Iran's MOIS cyber operations unit.
MITRE ATT&CK techniques used in TL-2026-0160
credential-access
T1003.001 LSASS Memory; T1003.004 LSA Secrets; T1555.003 Credentials from Web Browsers
collection
T1005 Data from Local System; T1056.001 Keylogging; T1113 Screen Capture; T1560.001 Archive via Utility
defense-evasion
T1027 Obfuscated Files or Information; T1027.003 Steganography; T1027.004 Compile After Delivery; T1027.010 Command Obfuscation; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.003 CMSTP; T1218.005 Mshta; T1480 Execution Guardrails
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1047 Windows Management Instrumentation; T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1059.006 Python; T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File; T1559.001 Component Object Model
command-and-control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1104 Multi-Stage Channels; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography
discovery
T1083 File and Directory Discovery; T1087.002 Domain Account
persistence
T1137.001 Office Template Macros; T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL
privilege-escalation
T1548.002 Bypass User Account Control
initial-access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
resource-development
T1583.006 Web Services; T1588.002 Tool
reconnaissance
defense-impairment
Weaknesses (CWE) in CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP
CWE-506, CWE-94, CWE-522
Timeline of CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP
- MuddyWater APT group first observed targeting Middle Eastern organizations. Attribution to Iran MOIS. Source: https://reaqta.com/2017/11/muddywater-apt-targeting-middle-east/
- U.S. Cyber Command CNMF publicly attributes MuddyWater as subordinate element of Iran MOIS. Publishes malware samples to VirusTotal. Source: https://www.cybercom.mil/Media/News/Article/2897570/
- FBI/CISA/CNMF/NCSC-UK publish joint advisory AA22-055A documenting MuddyWater TTPs including PowGoop, Small Sieve (Telegram Bot C2), Canopy/Starwhale, Mori, POWERSTATS. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a
- First indicators of CHAR Rust backdoor and GhostFetch/HTTP_VIP downloaders observed in the wild. Infrastructure analysis links to historic MuddyWater C2 ranges.
- GhostBackDoor secondary backdoor identified in same campaigns. AI-assisted code generation patterns detected across all four malware components.
- Network infrastructure overlap confirmed between CHAR campaign C2 servers and historic MuddyWater operations. Telegram Bot API C2 channel evolution from Small Sieve documented.
- SentinelOne Week 9 summary covers Operation Olalampo, confirming CHAR Rust backdoor with Telegram bot C2, GhostFetch/HTTP_VIP downloaders, AI-assisted malware development, and infrastructure reuse from late 2025. Cites Group-IB original research.
- Threadlinqs publishes TL-2026-0158 (MuddyWater Operation Olalampo) — predecessor analysis confirming active MuddyWater operations. Source: https://intel.threadlinqs.com/threat/TL-2026-0158
- UK NCSC publishes weekly threat report identifying CHAR, GhostFetch, HTTP_VIP, and GhostBackDoor as new MuddyWater malware variants with AI-assisted development indicators. Source: https://www.ncsc.gov.uk/report/weekly-threat-report
- As of 2026-05-29, this threat remains ACTIVE: MuddyWater's Operation Olalampo (CHAR Rust backdoor, GhostFetch, GhostBackDoor, HTTP_VIP) is an ongoing AI-assisted MENA campaign first seen Jan 2026, with MOIS-linked Seedworm intrusions reported on US/Israeli networks through Mar 2026. No CVE to patch, no successor supersedes it, and no confirmed disruption of MuddyWater despite reported strain on Iran's cyber apparatus.
Threats related to CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP
- MuddyWater Operation Olalampo — Iran MOIS-Nexus APT Deploys New Malware Variants with Telegram Bot C2 Targeting Middle Eastern Governments and Critical Infrastructure
- Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and SentinelOne Binaries, ChromElevator Browser Theft, Node.js/PowerShell Implant Chain
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign
Detection coverage for TL-2026-0160
As of 2026-03-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0160 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.