Kalim
Kalim is a backdoor referenced in Group-IB reporting on MuddyWater’s 2026 Operation Olalampo campaign. In the reported intrusion chain, a Rust backdoor named CHAR—controlled via a Telegram bot—used a PowerShell command designed to execute either a SOCKS5 reverse proxy or another backdoor named Kalim. The broader campaign was first observed on 2026-01-26 and primarily targeted organizations and individuals across the Middle East and North Africa using phishing emails with malicious Microsoft Office attachments containing macro code. Those macros decoded and executed embedded payloads to establish remote control. Group-IB attributed the activity to MuddyWater, the Iranian threat actor also known as Earth Vetala, Mango Sandstorm, and MUDDYCOAST. Based on the provided content, Kalim is associated with MuddyWater-linked post-compromise activity as an additional payload/backdoor executed by CHAR. No further technical details, platform specifics, persistence mechanisms, or standalone indicators of compromise for Kalim are provided in the source content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The PowerShell command is designed to execute a SOCKS5 reverse proxy or another backdoor named Kalim...
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Additional backdoor referenced as being executed/deployed via CHAR-driven PowerShell commands.
Additional backdoor referenced as being executed via CHAR-delivered PowerShell commands (details not further described in the content).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.