GhostBackDoor is a Windows backdoor associated with the Iranian state-linked threat actor MuddyWater and documented in Operation Olalampo, a cyber-espionage campaign targeting organizations and individuals in the Middle East and North Africa. It is typically deployed as a second-stage implant by the GhostFetch downloader after spearphishing-based initial access using malicious Microsoft Office documents with macro execution. Reporting also links GhostBackDoor variants to later MuddyWater activity against strategic sectors including energy, maritime, diplomatic, financial, telecommunications, and other critical infrastructure-related targets in the region.
The malware functions as a persistent post-exploitation implant designed to provide remote operator access on compromised systems. Its confirmed capabilities include interactive shell access for remote command execution, file read and write operations, and the ability to trigger re-execution of GhostFetch to retrieve or refresh additional payloads. In campaign reporting, GhostFetch has been described as fetching GhostBackDoor over HTTP, decrypting payloads, and reflectively loading them into memory, indicating that GhostBackDoor can be used as part of a memory-resident multi-stage intrusion chain intended to reduce visibility and support longer-term access.
GhostBackDoor is part of a broader MuddyWater toolset that has included custom backdoors, downloaders, and abuse of legitimate remote management software. Within Operation Olalampo, the malware was used alongside GhostFetch, HTTP_VIP, and the Rust-based CHAR backdoor in tailored spearphishing waves against MENA targets. The overall operational objective of these campaigns has been espionage, including persistent access, remote control, and collection of victim data rather than overt disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...the threat actor is said to have conducted four distinct waves of attack, leading to the deployment of various malware families, including GhostBackDoor and Nuso... | CVE-2025-54068 (CVSS score: 9.8) - A code injection vulnerability in Laravel Livewire that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. (Fixed in July 2025)
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign delivered four novel malware families (CHAR, GhostFetch, GhostBackDoor, HTTP_VIP) against MENA targets via spearphishing.
The campaign delivered four novel malware families (CHAR, GhostFetch, GhostBackDoor, HTTP_VIP) against MENA targets via spearphishing.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Telegram как C2 - Web Protocols (T1071.001) - выбор со смыслом: TLS-шифрование, telegram.org нередко присутствует в whitelist корпоративных прокси.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A novel backdoor malware family used in Operation Olalampo and delivered via spearphishing against MENA targets.
A novel backdoor malware family delivered in Operation Olalampo against MENA targets via spearphishing.
Backdoor delivered by GhostFetch; described as an AES-encrypted PE reflectively loaded into memory.
Backdoor malware deployed by MuddyWater during a sustained campaign against a UAE marine and energy company.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.