Back main.whoisxmlapi.com A Dns Exploration Of Operation Olalampo
MuddyWater has long been active in state- cyber operations. In its latest campaign, dubbed “Operation Olalampo,” the group targeted organizations and individuals primarily across the MENA region, leveraging geopolitical tensions. The attackers deployed new malware variants and used Telegram bots for command-and-control (C&C).
Group-IB identified 1 seven network IoCs associated with the activity. We analyzed all seven IoCs, comprising four domains and three IP addresses, and confirmed that none were tied to legitimate ownership. Using our homegrown tools to investigate the threat, we uncovered these findings:
Download a sample of the threat research materials now or sales to your intelligence needs for threat detection and response or other cybersecurity use cases.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
