MuddyWater, also tracked as GreenGolf and Mango Sandstorm, is an Iranian state-linked cyber espionage actor. The group is associated with spearphishing-led intrusion activity across the Middle East and North Africa and is known for using custom malware and evolving delivery chains to support intelligence collection and broader Iranian cyber operations. Reporting on 2026 activity indicates the actor incorporated generative AI into parts of its malware-development workflow, reinforcing a pattern of adapting new tooling to established tradecraft rather than fundamentally changing its operational model. In Operation Olalampo, first observed in January 2026, the actor targeted MENA entities through spearphishing and deployed multiple novel malware families, including CHAR, GhostFetch, GhostBackDoor, and HTTP_VIP. Analysis of the Rust-based CHAR backdoor indicated likely AI-assisted code generation in some components. This activity aligns with broader assessments that Iranian operators used large language models and generative AI to accelerate reconnaissance, social engineering, code development, and malware refinement. The actor’s observed behavior in the available reporting supports capabilities in initial access via spearphishing, persistence, post-exploitation, exfiltration, and defense evasion through tailored malware and remote-access tooling. MuddyWater is widely recognized as part of Iran’s state-sponsored cyber ecosystem and is primarily assessed as an espionage-focused threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian threat actor behind Operation Olalampo, using spearphishing to deliver multiple malware families against MENA organizations and reportedly leveraging AI-generated code segments in malware development.
Iran-linked actor behind Operation Olalampo, delivering multiple novel malware families via spearphishing against MENA targets and reportedly experimenting with Gemini for file transfer and remote execution code.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.