#GhostFetch
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
February 23, 2026 at 2:32 PM
Iran's APTs are shipping AI-written malware that runs entirely in memory - and finding live US ICS in 5 minutes. https://intel.threadlinqs.com/threat/TL-2026-1417 #ThreatIntel #GhostFetch #GhostBackDoor #HTTP_VIP
July 16, 2026 at 1:14 PM
MuddyWater is actively attacking MENA organizations using GhostFetch, CHAR, and HTTP_VIP malware to maintain access and steal info. Stay alert and secure your networks 👇
👉 sctocs.com/muddywater-m...

#Security #CyberThreats
#cybersecurity #sctocs
MuddyWater Targets MENA Organizations Using GhostFetch, CHAR, And HTTP_VIP - SCtoCS
MuddyWater is targeting MENA organizations with GhostFetch, CHAR, and HTTP_VIP malware, expanding cyber espionage operations across the region.
sctocs.com
February 23, 2026 at 7:15 PM
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
thehackernews.com
February 23, 2026 at 8:46 AM
February 23, 2026 at 7:00 PM
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (M…
#hackernews #news
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. The activity, first observed on January 26, 2026, has resulted in the deployment of new malware families that share
thehackernews.com
February 24, 2026 at 1:48 AM
Hidden Cyber Threats Exposed: MuddyWater’s Stealth Campaign Targeting MENA Organizations

Introduction: A Silent Cyber Offensive Unfolds Cybersecurity researchers have uncovered a sophisticated and persistent attack campaign targeting organizations across the Middle East and North Africa (MENA). At…
Hidden Cyber Threats Exposed: MuddyWater’s Stealth Campaign Targeting MENA Organizations
Introduction: A Silent Cyber Offensive Unfolds Cybersecurity researchers have uncovered a sophisticated and persistent attack campaign targeting organizations across the Middle East and North Africa (MENA). At the center of this operation is a threat actor known as MuddyWater, a group widely associated with espionage-driven cyber activities. Leveraging advanced malware tools like GhostFetch, CHAR, and HTTP_VIP, the attackers are executing stealthy intrusions designed to extract sensitive data while remaining undetected for extended periods.
undercodenews.com
April 30, 2026 at 11:58 PM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Monday, February 23, 2026
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
MuddyWater’s Operation Olalampo targets MENA with GhostFetch, CHAR, HTTP_VIP, and AI-assisted malware since Jan 26, 2026.
thehackernews.com
February 24, 2026 at 10:14 AM
⚡ MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

#Cybersecurity #Security
Sentiments: negative
The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. The activity, first observed on January 26, 2026, has resulted in the deploy...
techsentiments.com
February 23, 2026 at 12:37 PM
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html
February 23, 2026 at 8:47 AM
イランのAPTグループが地政学的緊張の高まりの中で重要インフラへのサイバー攻撃を加速

中東の緊張が劇的に高まり始めたのは先週のことで、米国とイスラエルの共同軍事作戦「ライオンの咆哮作戦」によるイランの核・軍事施設への攻撃が引き金となりました。 イランは報復としてミサイルと無人機で対抗し、湾岸地域のエネルギー、航空旅客、外交的安定性を混乱させました。この実力紛争の最中、イラン政府系の高度な持続的脅威(APT)は世界中の重要インフラを標的としたサイバー作戦を強化しています。 Nozomi Networks…
イランのAPTグループが地政学的緊張の高まりの中で重要インフラへのサイバー攻撃を加速
中東の緊張が劇的に高まり始めたのは先週のことで、米国とイスラエルの共同軍事作戦「ライオンの咆哮作戦」によるイランの核・軍事施設への攻撃が引き金となりました。 イランは報復としてミサイルと無人機で対抗し、湾岸地域のエネルギー、航空旅客、外交的安定性を混乱させました。この実力紛争の最中、イラン政府系の高度な持続的脅威(APT)は世界中の重要インフラを標的としたサイバー作戦を強化しています。 Nozomi Networks はイラン関連のAPTアラートの急増を報告しており、製造業と運輸セクターが優先されています。 テレメトリーデータは紛争初期段階での攻撃の体系的な増加を示しており、過去の紛争では133%の増加が見られました。MuddyWater、OilRig、APT33、UNC1549などのグループがこの急増を主導しており、スパイ活動と破壊工作に焦点を当てています。 MuddyWater(別名APT34、Seedworm)はイランの情報セキュリティ省(MOIS)に関連しており、スピアフィッシング、認証情報の盗難、および生存地帯技術を使用して持続性を確保しています。最近、GhostFetchなどのカスタムマルウェアを使用してオペレーション・オラランポでMENA地域の組織を標的にしました。 イランのAPTグループ OilRig(APT34、Helix Kitten)は、中東のエネルギーおよび通信セクターに対して、フィッシング、Webシェル、およびスパイ活動のためのPowerShellを使用しています。 APT33(Elfin、Refined Kitten)はサプライチェーン攻撃とパスワードスプレーを通じて航空宇宙、エネルギー、政府セクターを攻撃します。2025年下半期に活動しているUNC1549はイランの優先事項に合致した防衛および通信セクターを標的にしています。 脅威アクター 別名 主要な標的 主要なTTP(Nozomi Networks) MuddyWater APT34、OilRig エネルギー、通信、政府 スピアフィッシング、LOLBins OilRig APT34、Helix Kitten 金融、防衛 Webシェル、認証情報の収集 APT33 Elfin 航空宇宙、エネルギー パスワードスプレー、サプライチェーン UNC1549 CURIUM 防衛、通信 スパイ活動、破壊工作 中東の攻撃対象領域の脆弱性 中東の組織は高い脆弱性の露出を示しており、2025年に発見された欠陥の61%が高/重大なCVSSスコアを有しており、世界平均の48%と比較しています。EPSSスコア>1%は脆弱性の8%に影響を及ぼし、これは世界平均の2倍です。エアギャップのみでは不十分であり、効率的なパッチ適用が不可欠です。 最近の中東での検出における主なMITRE ATT&CK TTPには、デフォルト認証情報の悪用(T1110)、有効なアカウントの使用(T1078)、ブルートフォース攻撃(T1110.001)、スキャン(T1595)が含まれます。これらは将来の破壊工作のための初期偵察を示す信号です。 イランのTTPに対する高まったアラート感度を備えた継続的なOTモニタリングを有効化してください。脅威インテリジェンスシグネチャーを更新し、Nozomiの顧客はリアルタイムフィードを有効にする必要があります。 脆弱性にパッチを当て、デフォルト認証情報を変更し、IT/OTセグメンテーションを再評価してください。産業用プロトコルをベースライン化し、MuddyWaterのようなグループに対する検出を検証してください。 ネットワークトラフィック内の低速かつ遅いアクティビティを探してください。サイバーと物理的なリスクを融合したハイブリッド脅威に対するインシデント対応を準備してください。可視性、セグメンテーション、テスト済みプランを融合させた組織がこれらのキャンペーンに最も耐えることができます。 翻訳元:
blackhatnews.tokyo
March 4, 2026 at 10:43 AM
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several orga...

Origin | Interest | Match
February 23, 2026 at 10:05 AM
The Iranian hacking group MuddyWater is targeting MENA organizations with new malware like GhostFetch, CHAR, and HTTP_VIP as part of Operation Olalampo.

thehackernews.com/2026/02/mudd...
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
MuddyWater’s Operation Olalampo targets MENA with GhostFetch, CHAR, HTTP_VIP, and AI-assisted malware since Jan 26, 2026.
thehackernews.com
February 23, 2026 at 12:45 PM
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP - CyberSecurity
Ravie LakshmananFeb 23, 2026Threat Intelligence / Artificial Intelligence
cybersecurity.rozeepk.com
February 23, 2026 at 11:35 AM
イランのハッカー集団MuddyWaterがMENA地域組織を狙い、新マルウェアGhostFetchなどを展開。
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
MuddyWater’s Operation Olalampo targets MENA with GhostFetch, CHAR, HTTP_VIP, and AI-assisted malware since Jan 26, 2026.
thehackernews.com
February 23, 2026 at 8:01 AM
Recently,
@GroupIB
reported on #MuddyWater’s Operation Olalampo, which introduced a new downloader named #GhostFetch.

While analyzing GhostFetch, our code similarity engine identified strong overlap…

🔁 RT @ThreatrayLabs | reposted by @craiu
https://x.com/ThreatrayLabs/status/2027005103119511923
February 26, 2026 at 3:11 PM
#MuddyWater is back with #OperationOlalampo, deploying four new malware families including CHAR – a rust backdoor, GhostFetch – a loader that deploys GhostBackDoor, and HTTP_VIP – a loader and a backdoor.…

🔁 RT @GroupIB_TI | reposted by @cyb3rops
https://x.com/GroupIB_TI/status/2024800744189071442
February 21, 2026 at 10:13 AM