HTTP_VIP is a Windows-native downloader associated with the Iranian state-linked threat actor MuddyWater and documented in Operation Olalampo, a cyber-espionage campaign targeting organizations and individuals across the Middle East and North Africa. It has been delivered through spearphishing emails carrying malicious Microsoft Office documents that rely on macro execution, including travel- and business-themed lures. After execution, HTTP_VIP performs system reconnaissance, communicates with command-and-control infrastructure, and is used to deploy the legitimate remote management tool AnyDesk to provide operators with remote access while blending into normal administrative activity. Reported newer variants extend beyond simple delivery by gathering victim information, executing commands, supporting interactive shell access, transferring files, and capturing clipboard contents. The malware fits MuddyWater’s broader tradecraft of combining phishing, staged payload delivery, abuse of legitimate remote management software, and persistent espionage-focused access against regional government, maritime, energy, financial, telecom, and other MENA targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign delivered four novel malware families (CHAR, GhostFetch, GhostBackDoor, HTTP_VIP) against MENA targets via spearphishing.
The campaign delivered four novel malware families (CHAR, GhostFetch, GhostBackDoor, HTTP_VIP) against MENA targets via spearphishing.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Sekoia TDR (July 2024) independently documented the same implant under the name MuddyRot, with matching characteristics: mutex “DocumentUpdater,” TCP port 443, and identical string obfuscation logic.
Command & Control / Exfiltration: Custom C2 (HTTP, encrypted channels), data staging (T1071.001, T1041).
"The campaign used phishing, post-exploitation tooling, and Telegram-based command and control..."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A novel malware family used in Operation Olalampo and delivered via spearphishing against MENA targets.
A novel malware family delivered in Operation Olalampo against MENA targets via spearphishing.
Loader used to fetch and install AnyDesk as the next-stage remote access tool over HTTP.
A Windows-native downloader used by MuddyWater to deliver AnyDesk RMM via hardcoded C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.