Iranian nation-state threat group MuddyWater has launched Operation Olalampo, a new attack campaign targeting organizations in the Middle East, North Africa, and Africa. The campaign uses spear-phishing emails with malicious Microsoft Office documents to deploy several never-before-seen malware strains: the Char backdoor (Rust-based, using Telegram as C2), GhostFetch downloader with GhostBackDoor, and HTTP_VIP downloader that deploys AnyDesk RMM. Notably, the malware shows signs of AI-assisted development, evidenced by debug strings containing emojis in the code. MuddyWater is also experimenting with exploiting public-facing server vulnerabilities as an alternative entry point, marking a tactical evolution for the group. Group-IB researchers recommend defenders use the published IoCs, YARA rules, and EDR rules to monitor for activity.