Skip to content

Kalim

Kalim is a backdoor referenced in Group-IB reporting on MuddyWater’s 2026 Operation Olalampo campaign.

Profile source: Mallory opens in a new tab

Kalim

Family profile

Kalim is a backdoor referenced in Group-IB reporting on MuddyWater’s 2026 Operation Olalampo campaign. In the reported intrusion chain, a Rust backdoor named CHAR—controlled via a Telegram bot—used a PowerShell command designed to execute either a SOCKS5 reverse proxy or another backdoor named Kalim. The broader campaign was first observed on 2026-01-26 and primarily targeted organizations and individuals across the Middle East and North Africa using phishing emails with malicious Microsoft Office attachments containing macro code. Those macros decoded and executed embedded payloads to establish remote control. Group-IB attributed the activity to MuddyWater, the Iranian threat actor also known as Earth Vetala, Mango Sandstorm, and MUDDYCOAST. Based on the provided content, Kalim is associated with MuddyWater-linked post-compromise activity as an additional payload/backdoor executed by CHAR. No further technical details, platform specifics, persistence mechanisms, or standalone indicators of compromise for Kalim are provided in the source content.

Observed infrastructure

Last seven days

First activity
Aug 8, 2026
Last activity
Aug 8, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
MuddyWater

The PowerShell command is designed to execute a SOCKS5 reverse proxy or another backdoor named Kalim...

MITRE ATT&CK

Kalim in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.