
Threat Talks · 2026-06-16 · 22 min
Key moments - from our scoring
Substance score
56 / 100
Five dimensions, 20 points each
This episode examines Muddy Water, an Iranian civilian intelligence-affiliated APT group that focuses on brokering network access in the Middle East and North Africa, with recent expansion toward US targets. The discussion centers on their Olalampo campaign, which leverages Office document macros as the primary delivery mechanism. Once executed, the malware installs three persistence mechanisms: a Telegram bot C2 channel designed to blend with legitimate user traffic, a Rust-compiled ghost backdoor connecting to attacker-controlled domains, and a pre-configured legitimate AnyDesk remote access tool. Yuri Wit and Rob Maas explore both the attack chain and defensive strategies, emphasizing that while the techniques appear relatively straightforward compared to other state actors, their effectiveness stems largely from user behavior and organizational gaps. Key defenses include email filtering, macro disabling, EDR solutions monitoring behavioral anomalies, network segmentation, and blocking unauthorized outbound connections. The episode highlights how Muddy Water's use of legitimate tools and encryption-wrapped C2 channels creates detection challenges, and notes evidence of AI involvement in malware development.
Muddy Water is a nation-state APT group heavily associated with Iranian civilian intelligence, primarily targeting organizations in the Middle East and North Africa region, though recently expanding to US targets.
Muddy Water delivers malware via specially crafted Word documents with embedded macros that auto-execute when opened or enabled, dropping three backdoor mechanisms for network persistence.
Telegram is used because its TLS-encrypted traffic blends with legitimate user communications, making it difficult for security teams to distinguish C2 activity from regular chat applications.
The ghost backdoor is a Rust-compiled malware family that connects to attacker-controlled domains hosting dummy websites, enabling POST/GET request-based communication between the infected client and the attacker's C2 infrastructure.
The most effective defenses include email filtering to prevent macro-laden documents, disabling macros by default, deploying EDR solutions to detect malicious behavior, implementing network segmentation, and blocking unauthorized outbound connections using threat intelligence on known C2 addresses.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers moderately useful technical details about Muddy Water's tactics (Telegram C2, Rust malware, AnyDesk persistence) but is heavily padded with explanation of basic security concepts and back-and-forth dialogue that doesn't advance understanding. For a B2B operator, the core insight - that Iran-backed actors use macro-enabled Office documents with multiple persistence mechanisms - is solid but not deeply novel, and much of the runtime is spent re-explaining standard defenses (EDR, email filtering, network segmentation) that any security leader already knows.
they really, really like to infiltrate networks using office files. So Excel sheets or word documents with embedded macros in them that drop backdoors and command and control malware and persistence
the telegram bot on your system that the attackers can then basically control via a telegram channel that they own
The discussion relies heavily on publicly available APT frameworks and well-known defensive patterns (disable macros, use EDR, network segmentation, zero trust). The observation about Rust's inherent obfuscation is interesting but brief and not deeply explored. The Telegram C2 hiding technique is noteworthy but presented without novel analysis of why this is particularly effective or how detection should evolve. Most of the take-aways are standard security hygiene recycled across dozens of threat briefings.
they really just want to be very quiet. I mean that's pretty general in most APTs
Rust is a low level programing language, a pretty recent compared to the others like C&C, C++, but what makes rust interesting from a security perspective is that analyzing rust malware, or just rust executables in general, is a lot harder
Yuri Wit is a security analyst and researcher at ON2IT's SOC with credible technical depth on malware analysis, Rust compilation, and APT tactics. However, he is not identified as having hands-on experience defending against or responding to actual Muddy Water intrusions at scale, and the episode positions him as a 'red team proxy' rather than a practitioner with real operational scars. Rob Maas contributes defensibly but mostly reiterates standard Blue Team controls. Neither guest is a household name or someone known for major research publications on Iranian cyber operations.
He is a security analyst and a security researcher here at the SOC. Today he represents the red team
He is going to help us understand how we should defend against attacks that Yuri is going to be launching
The episode names Muddy Water, Operation Olalampo, and mentions specific tools (Telegram, Rust, AnyDesk, EDR) and techniques (macro-enabled Office docs, C2 over Telegram, Ghost backdoor). However, there are almost no concrete indicators of compromise, file hashes, C2 IP addresses, timeline details, or specific victim organizations. The claim about 'indications of AI being used' is vague and never substantiated. A B2B operator would struggle to translate this into actionable threat intelligence or specific detection rules.
Muddy Water is a nation state group from Iran. At least it's associated heavily with the civilian intelligence of Iran
there's a group called Muddy Water
The host asks reasonable setup questions but rarely pushes back on claims or demands deeper explanation. When Yuri makes vague statements (e.g., 'indications of AI' with no specifics), the host accepts it without follow-up. The dialogue is friendly and conversational but lacks the sharpness needed to extract nuance - for example, no one presses on why Muddy Water's recent shift to US targets was unsuccessful, or what specific defenders missed. The conversation reads as genteel explanation rather than investigative interrogation.
Comment. There's an excellent question. Let me figure it out for you
So that's actually interesting that you mentioned that because one of the researchers that actually delved into the malware found from the Olalampo campaign found indications of AI being used to develop the malware. Now, there weren't a lot of specifics
Computed from the transcript - who did the talking, and the words that came up most.
Every big nation state has a cyber army: China, Russia, the US, Europe. But what about Iran? Meet Boggy Serpens, a group tied to Iran’s civilian intelligence service whose entire business is breaking in and staying in, then handing the keys to whoever strikes next. Their playbook, Operation OLALAMPO, needs just one booby-trapped Word document to plant three separate backdoors on your network. A Telegram-bot command channel that hides inside everyday encrypted chat traffic, a Rust “Ghost” backdoor built to defeat analysis, and a legitimate AnyDesk install quietly turned against you. The layered defense for every stage: email and file controls, behavioral EDR, egress policy, threat intel, and Zero Trust segmentation. The twist: why this operation mostly failed, plus the tells that the malware was partly written with AI. Filmed live at the ON2IT SOC, host Lieuwe Jan Koning runs a red team vs blue team session with analysts Yuri Wit, the “proxy Iranian” attacker, and Rob Maas on defense. Watch the full episode to see each move, and the exact control that stops it. Episode resources, transcript and show notes: ️
Transcribed and scored by The B2B Podcast Index.
We all know that every big nation state has a cyber army. What about Iran? Welcome to Threat Talks. My name is Lieuwe Jan Koning and here from the Security Operations Center at ON2IT, we bring you the next episode.
Let's get on to it. Welcome to Threat Talks. Let's delve deep into the dynamic world of cybersecurity. And let me introduce my two regular guests of the show.
First of all, Yuri Wit, welcome. He is a security analyst and a security researcher here at the SOC. Today he represents the red team. So he is our proxy Iranian for today.
And on the other side, it's Rob Maas. The blue lights on the back will give it away for you. He is going to help us understand how we should defend against attacks that Yuri is going to be launching. So that's the setup for today.
Let's dive in because yeah, like I said what about Iran? Of course there's been a lot of turmoil at the moment at a geopolitical theater. So we wondered we know that China and America and Europe and Russia have their cyber arms. But what can we say about Iran?
And you actually dove in and, well, we do have a thing. And I really have to look at my cards. It's a group called Muddy Water. I'm I want to know from you if you know who made that name or whether to name them.
And the operation we're going to talk about. Is the operation a real tongue twister? All right. Oh, operation.
Yeah. So can you explain a little bit about what we are facing here? Yeah. So Muddy Water is a nation state group from Iran.
At least it's associated heavily with the civilian intelligence of Iran, one of three nation states attackers that we know of that are sponsored by Iran. Their main targets so far have normally just been in the Mena region, the middle inner region, Mena region on Middle East and North Africa. Although lately with geopolitical tensions, they have shifted a bit to the US. And yeah, their main focus is usually to broker access.
So they're the ones that actually infiltrator networks gain persistence. And then either sell that or give that to the other Iranian nation states or X trade data with it. That's kind of their whole deal. Yeah, you probably don't know where they are at.
And if they're really government or a commercial party or. Right, it's a bit missing. Sure. I mean, that's always with nation state.
Attackers are never able to specifically know where they're from, what they're from, who actually signs the checks. But it is highly likely that this is from the who is the specific agency within the Iranian government from a civilian identity? Do you say so? Why do you think so?
Purely due to apt markers. I mean, the most common method of determining that is just comparing different attacks with each other based on the monitor attack framework. And if you see two attacks that are very similar in the techniques and the tactics that they use, then you can basically merge the info that you have for both of them. Do that a couple times and eventually you'll develop a bigger likely because the reason because if you have a toolbox on how to attack, it's not.
There's a lot of effort in there. So you're not easily going to switch those. So therefore and everybody makes their own and therefore we know this is this rush and this is our identification based on behavior. Basically you mentioned identity broker.
What do you mean by actually broker. Yeah. It means that they facilitate entry into target networks. So again they gain entry.
They get persistence like C2 a command and control access or just straight a backdoor somewhere, either to do something with it themselves. Or they can also hand over that access to other organizations that are aligned. It's a nation specific managed service that the government can use to make sure that, yeah, actually they provide the weapon and then their government can execute it well. Yeah, exactly.
Yeah. All right. Yeah. Well, so far, Rob has nothing to defend against.
So tell us what. What do they do? You look at the operation or the Lumpur. What what what happened there?
So for Olalampo. But what what is pretty generic in all their attacks that have so far been attributed to muddy water is that they really, really like to infiltrate networks using office files. So Excel sheets or word documents with embedded macros in them that drop backdoors and command and control malware and persistence. There's going to be a very short episode of threat Talks because a lot.
What's your opinion on on macros in office files you see disable them. That's, if possible. Well, there will always be exceptions. But it starts a bit before that, so you need to deliver.
Of course, the, the macro file. So I think you should start there with trying to prevent a user from receiving it or able to click on it. So that could be maybe with your email filtering, deny maybe just office files and use different platforms to exchange those files. That could be an option.
You have, of course, all kinds of email security settings that you can use to only allow specific domains, or at least maybe some domains are not trustworthy. You can block them. And if a user simply still has the file on the computer, then there's also still tools like EDR that can, block the execution of macros. Or at least if it is an unexpected or at least malicious behavior.
Yeah, because you can be sure like right now it's via email. But if email would be blocked then there's different ways, right? Yeah. Then of course yeah a better a okay.
But this is done a very simple like a tech. You think I mean not normally in a macro should be relatively easy to defend against. Yeah. But apparently it's effective then.
It is. It is. But unfortunately the reason behind that is user error, a very common tactic in all of these infected Microsoft Office documents is that they'll either blur the text or they'll print like a top layer onto the Excel sheet saying, oh, this is not working on your current machine. You should enable macros and actually giving the user specific instructions, because normally on windows installations, if you install office untrusted files from the internet with the mark of the web will not have macros enabled by default.
So we actually get that pop up either saying, oh, enable editing or enable macros. And so they'll embed layers into their documents that. Tell the user to specifically enable those macros. So yes, by just disabling macros, that helps.
However, if you need macros for business reasons, then you're still relying on the human element to not enable them once they receive a sketchy file. All right, so apparently there is a specially crafted word document file that I have in my inbox. Apparently I click it because that's my, my mojo. Right.
And then what happens? So yeah. Well, you open the documents, the macros execute their auto executes at the moment that you either open the document or enable macros. And then it does three things.
It installs two different types of backdoors. And it also enables communication via a different C2 setup. So it's quite novel the way that they do that is they it really aligns with their objective to just get access and gain persistence in a target network, because they basically delivered three methods to do so. The first one is via a C2 endpoint that communicates via a telegram bot.
So basically installs a telegram bot on your system that the attackers can then basically control via a telegram channel that they own another way. One moment for this. So and the whole reason they do this is though. So I mean, if you have an initial foothold on a machine, then it's nice to be for the attacker to remote control.
And that's why it's set up sets up. So why telegram. Well that's actually a pretty interesting one. So I mean in different countries the main chat app will be different in the Netherlands.
Over here it's WhatsApp. Pretty much everybody uses WhatsApp, but in other countries maybe they use telegram and apparently they seem to think so. What seems to think so? They most likely use telegram specifically to blend in with all the other network traffic, because that C2 traffic is all TLS encrypted, so you can't see any of it, and it's going towards telegram.
So a SOC team might have a very hard time identifying the difference between C2 communication via telegram and just regular chatting from users. Yeah, because it looks exactly the same as a user who is chatting and it basically poses as a regular user, but stead of talking to to another human, it actually talks to another machine, which is a C2 server of the attacker. Exactly. And it's really hard to detect this way.
Yeah. Okay. So that's that's the C2 channel. But there's two backdoors that you also put on.
You said, well there are two C2 channels and then another back door, although the naming gets a bit confused because technically the other C2 channel is also called a ghost backdoor. That's, that's the name that was given to that malware family. But that is a lot more like regular C2 traffic. It just connects to a domain.
That domain hosts some either a blank or a dummy website, but behind the scenes it actually requests or an enabling Post requests and allows communication between the infected client and attacker owned C2 infrastructure. So this sounds like A plan a a in a plan B for command and control. How do we combat this role? Yeah.
Server ways what we can do. First of all try to prevent that. The files are being stored. And if they are stored try to prevent that they are being executed.
So EDR again will help you hear. It can keep track of every process that's been running. Yeah. Because they should have eradicated the macro.
Yeah. Containing doc file for example. Yeah okay. So and once it's been run EDR will check for behavior.
Well if it is only solely C2 that's kind of a harmless behavior. It's just a network connection. So probably won't trigger on that. And then you need some kind of network policies in place to prevent traffic going to places you don't want to go to.
For example, why should a client or desktop connect to a telegram server? And maybe you have a business policy that allows it and it will be hard, but otherwise deny all traffic? That's not not necessary. It's harder on endpoint, I guess.
I mean on the server. You on the server certainly know relatively easy, but this is not executed on exactly. And yeah, well, I'm not sure if it is unfortunate often that we live in an age where we allow internet access, or at least at most companies, users get internet access to almost everything instead of allow listing what we typically do in security. So then it becomes hard to block these, these commander control servers, but it helps to have up to date, threat interferes with the known C2 IP addresses, for example, and block all that access.
So there are a few things that we can do here. But in general, try to block all outgoing connections where it's not needed, because the most effective so far for the controversy that you've listed for this part, I think since this is an end user computer, I would say a good EDR solution that really looks at behavior, running processes, outgoing connections, etc. and that everything together to see if it is could be malicious or not. Okay.
Clear. Yeah. So yeah, just establishing a command and control channel is harmless. You could say if you don't use it.
Technically. Yeah. Yeah. So what happens?
Well, from that on, from then on, the attackers have access to the entire user's machine. I mean, if they allow the execution of macros, then it is highly likely that none of the other endpoint security improvements have also been made. So at that point, the attackers just have access to whatever files are on the the target's endpoint, whatever file shares are connected to it from that place on, they just start digging. Yeah.
So for this operation all along, the mission accomplished because the goal was to establish access. Right. So access and then exfiltrate data. Can you tell me about the techniques they used or the I don't know, programing language they used.
You already mentioned RC two works. There's you dug into it. Yeah. Yeah.
So they they really just want to be very quiet. I mean that's pretty general in most APTs, but it's especially prevalent in the attack where they not only use a telegram but as C2 to again hide in regular user traffic. But they also decided to make their more regular backdoor be built in rust, which is great. I love rust, but it's a programing language.
Yeah, rust is sorry. Yeah. Rust is a low level programing language, a pretty recent compared to the others like C&C, C++, but what makes rust interesting from a security perspective is that analyzing rust malware, or just rust executables in general, is a lot harder than in C and C++. It's like it has built in obfuscation that just makes the disassembly of the binaries much harder.
But and why is that true? Russ then what do they do different? I'm not entirely sure about that, but it must have something to do with the fact that rust is what they call a memory safe language. That's one of the primary talking points about rust is that the compiler does very strict type checking.
So making sure that the data that you put in your application is actually what the compiler should expect or what the rest of your code should expect, and also has a feature where the moment a variable. So again, data in your application is no longer necessary. It just throws it away immediately, making it completely inaccessible while in C&C plus plus, whenever you need to use memory, you allocate a certain amount of memory on the stack in your RAM usually, and then after you're done with it, you have to manually Delacorte and remove that data again.
And you know when that doesn't happen, then it's very easy to pull data from there. From a malware analysis standpoint, it's very easy to pull data from a binary while it's running in Rust. It's just a lot harder. Yeah, it's made with security in mind.
I mean, it's really hard to if it's if it's all possible to make a buffer overflow program because it's designed to not have those kinds of things and because of the endeavor becomes more dynamic, probably better optimized, and therefore it looks much more like rubbish. Yeah. If you compile it. So, exactly.
It's a good thing to if you attacker should always use rust, then definitely. Yeah. Right. All your malware in rust.
Yeah. Well everyone who uses C++ still I think is also a very good idea to do something like this. Okay. Anything else that you noticed that was interesting.
So they actually have a third method of gaining persistence, a third backdoor, basically via something very novel, the any desk application and not some infected version of the any desk application application, the team viewer, the remote assistance tool, the legitimate one. They download it from their own infrastructure that they host themselves. So it is preloaded with the settings to give the attackers access to it. But it is just the legitimate any desk binary, nothing special about it.
They they download it and they run it, and they make sure that it runs persistently on the endpoint so that they basically have RDP towards the, the, the targets at all times. It looks like it's a, it's a tool for the IT department actually installed. And therefore especially if you use the same tool, nobody's going to detect it. Exactly.
Yeah. Or do you have a trick. Well yeah. First of all, if you don't use the tool, make sure that that it can be installed.
So let's start there. So any that should not be on any computer if you don't use it yourself. And of course here as well you can control the connections. What connection is any desk allowed to make to which server.
And normally you know which server is is the one that you host or for and not the one that in this case Muddy Waters is running. It shouldn't be a loud rule to allow any desk traffic anywhere in your organization if you're not using the solution, correct. And certainly not to IP addresses that are somehow. Yeah.
Not yours. Yeah. Okay. You mentioned briefly, from then on, you can do anything, right?
Because you're the king of the king of the machine. I mean, and these things happen. I mean, sometimes people do get access to a single computer. Yeah.
I'm immediately thinking of why. Why would we have why would have desktop all kinds of access? Is there is there something else we can do in that area? Yeah.
So first of all, zero trust. Yeah. We've seen it. Search for us is the best strategy to watch.
I think every in general, every app or every attack. What we can of course do is lock down the machine. That's a good starting point. But in this case, if you already come this far, then apparently there's not much done on lockdown and then you can only rely, I think, on either having an EDR on the endpoint that the text anomalies so that you can at least see, okay, this endpoint is now doing something that it hasn't been done doing before.
So you can block it and exploit often after exploit. And also make sure that your endpoints, especially your clients, are in a separated segments in network segment so that you can strictly control network access from those endpoints to towards your service, where your crown jewels, your data lives. To make that even very hard for an attacker to simply hop over to those servers as well. Okay.
This is this is a sophisticated malware. I mean, and did they achieve their goal, for example? I mean, do we know anything about it? Typically it's hard for a to to analyze what a state actor achieves, right?
Because their goal is to not show that exactly or to stay to say, to stay in the background a little bit until they need it. Yeah. Anything you can say about it here? What did they try to do?
You mentioned a the the they recently swift shifted to the US. They got anything there I mean not really. Again it's always hard to say exactly what they got, but overwhelming evidence indicates that it wasn't super successful. The entire operation seemed to have pretty much just failed, I guess, that can be kind of attributed to the fact that the methods they use are kind of simple.
I wouldn't call them simple because it's still a nation state. I mean, it's still a little hard to pull off, but compared to the bigger ones, it is insignificant. So yeah, it's what you can see. Yeah.
Exactly. So yeah. Do they. For example, I mean we are talking about AI all the time.
Do they use this? Do we know this? I mean, for sure. Everybody who is developing uses this.
Do we see signs of it. So that's actually interesting that you mentioned that because one of the researchers that actually delved into the malware found from the Olalampo campaign found indications of AI being used to develop the malware. Now, there weren't a lot of specifics, but I think you can just translate that to. Or maybe they found a emojis in some source code file or some very blatant Em dashes or something like that in comments found somewhere.
Comment. There's an excellent question. Let me figure it out for you. Yeah, exactly.
Yeah. So it's it's the, the the the things that we also see if we get an email. This is clear. Yeah.
Yeah. That's kind of thing that that applies to nation state malware as well then. Yes. All right.
Well in summary I think we shouldn't be should we say that we are not too scared about this. Well, I mean, you should always remain vigilant about APTs, but in this case, like they're not impressed. I'm not super impressed compared to other APTs, I've been more impressed than in the past. I guess the most important is just educate your end users because it's all at the end of the day.
It's all phishing, spear phishing, but still phishing. So yeah, not super overwhelmingly interesting. I would say. Okay, well sometimes there's a little bit good news in cybersecurity.
Thank you very much. Thank you so much for explaining about this different branch of malware that we've seen. And to our audience, thank you very much for tuning in. If you liked what you heard today, like and subscribe our video, we would really appreciate it and hope to see you next time.
Bye bye! Thank you for listening to Threat Talks, a podcast by ON2IT cybersecurity and AMS-IX. Did you like what you heard? Do you want to learn more?
Follow Threat Talks to stay up to date on the topic of cybersecurity.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.