CHAR is a Rust-based backdoor associated with the Iranian state-linked threat actor MuddyWater and documented in Operation Olalampo, a cyber-espionage campaign active from January 2026 and focused primarily on organizations and individuals in the Middle East and North Africa. The malware has been delivered through spearphishing emails carrying malicious Microsoft Office documents with macro-based execution, and reporting also links the broader campaign to exploitation of recently disclosed vulnerabilities on public-facing servers for initial access. Targeting has included sectors such as energy, maritime, diplomatic, financial, telecommunications, and other regional organizations of intelligence interest.
CHAR is controlled through the Telegram Bot API over HTTPS, giving operators an application-layer command-and-control channel that blends with legitimate service traffic. Its documented functionality includes changing directories and executing system commands through cmd.exe or PowerShell. Reporting further indicates use of PowerShell to launch additional post-compromise components, including reverse-proxy capability, supplementary backdoors, and tooling used to steal browser data. Within MuddyWater’s multi-stage intrusion chains, CHAR serves as a persistent remote-access implant supporting espionage and follow-on operations rather than overt disruption.
The malware is part of a broader MuddyWater toolset that in the same campaign also included GhostFetch, GhostBackDoor, and HTTP_VIP, reflecting the group’s continued shift from primarily script-heavy tradecraft toward custom native implants and staged payload delivery. Multiple reports assess CHAR as showing signs of AI-assisted development, citing unusual emoji-bearing debug strings in compiled artifacts. High-confidence attribution places CHAR within MuddyWater activity conducted on behalf of, or aligned with, Iran’s Ministry of Intelligence and Security.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign delivered four novel malware families (CHAR, GhostFetch, GhostBackDoor, HTTP_VIP) against MENA targets via spearphishing. Group-IB’s analysis of the Rust-based CHAR backdoor identified debug strings containing emojis.
The campaign delivered four novel malware families (CHAR, GhostFetch, GhostBackDoor, HTTP_VIP) against MENA targets via spearphishing. Group-IB’s analysis of the Rust-based CHAR backdoor identified debug strings containing emojis.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
"GhostBackDoor... supports an interactive shell"; "...retrieve instructions to start an interactive shell"
Execution & Persistence: PowerShell/PowerGoop, Rust-based implants (RustyWater/CHAR/Archer RAT), registry Run keys, scheduled tasks (T1059.001, T1547.001).
Defense Evasion: Obfuscation, reflective loading, disabling security tools, living-off-the-land (T1027, T1620, T1562).
Decimal-encoded строка хранится в UserForm1.TextBox1.Text - элементе формы, невидимом пользователю. Макрос считывает строку, декодирует и записывает PE-файл на диск.
Sekoia TDR (July 2024) independently documented the same implant under the name MuddyRot, with matching characteristics: mutex “DocumentUpdater,” TCP port 443, and identical string obfuscation logic.
Telegram как C2 - Web Protocols (T1071.001) - выбор со смыслом: TLS-шифрование, telegram.org нередко присутствует в whitelist корпоративных прокси.
Excel lure (energy/maritime company) -> CHAR (Rust backdoor with Telegram C2).
Command and control operates through Telegram dead drops, JWT-authenticated HTTPS with randomized URI paths, and Cloudflare-fronted infrastructure that masks backend servers from conventional blocking.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A novel Rust-based backdoor used in Operation Olalampo, delivered via spearphishing against MENA targets. The report suggests parts of its code may have been AI-generated based on unusual emoji-containing debug strings.
A Rust-based backdoor used in Operation Olalampo against MENA targets, delivered via spearphishing. The report suggests AI-assisted code generation may have been used in its development.
Rust-based backdoor used as a final payload, providing command-and-control over the Telegram Bot API.
A Rust-based backdoor used by MuddyWater and controlled through a Telegram bot; debug strings suggest AI-assisted code generation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.