Skip to content
A Dns Exploration Of Operation Olalampo

A Dns Exploration Of Operation Olalampo

main.whoisxmlapi.com • April 11, 2026

MuddyWater has long been active in state- cyber operations. In its latest campaign, dubbed “Operation Olalampo,” the group targeted organizations and individuals primarily across the MENA region, leveraging geopolitical tensions. The attackers deployed new malware variants and used Telegram bots for command-and-control (C&C).

Group-IB identified 1 seven network IoCs associated with the activity. We analyzed all seven IoCs, comprising four domains and three IP addresses, and confirmed that none were tied to legitimate ownership. Using our homegrown tools to investigate the threat, we uncovered these findings:

Download a sample of the threat research materials now or sales to your intelligence needs for threat detection and response or other cybersecurity use cases.

Extracted Entities

APT Groups (1)

Attack Types (1)

Campaigns (1)

Platforms (1)