Last seven days
- First activity
- Aug 8, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Kalim is a backdoor referenced in Group-IB reporting on MuddyWater’s 2026 Operation Olalampo campaign.
Profile source: Mallory opens in a new tabKalim
Kalim is a backdoor referenced in Group-IB reporting on MuddyWater’s 2026 Operation Olalampo campaign. In the reported intrusion chain, a Rust backdoor named CHAR—controlled via a Telegram bot—used a PowerShell command designed to execute either a SOCKS5 reverse proxy or another backdoor named Kalim. The broader campaign was first observed on 2026-01-26 and primarily targeted organizations and individuals across the Middle East and North Africa using phishing emails with malicious Microsoft Office attachments containing macro code. Those macros decoded and executed embedded payloads to establish remote control. Group-IB attributed the activity to MuddyWater, the Iranian threat actor also known as Earth Vetala, Mango Sandstorm, and MUDDYCOAST. Based on the provided content, Kalim is associated with MuddyWater-linked post-compromise activity as an additional payload/backdoor executed by CHAR. No further technical details, platform specifics, persistence mechanisms, or standalone indicators of compromise for Kalim are provided in the source content.
Samples
Reported operators
The PowerShell command is designed to execute a SOCKS5 reverse proxy or another backdoor named Kalim...
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.