diff --git a/Iranian APT/Charming Kitten/README.md b/Iranian APT/Charming Kitten/README.md index 00a1603..b30147d 100644 --- a/Iranian APT/Charming Kitten/README.md +++ b/Iranian APT/Charming Kitten/README.md @@ -19,7 +19,7 @@ and Group-IB: https://www.group-ib.com/blog/muddywater-operation-olalampo/ The initial campaign targeted project engineers using industry-specific terminology for subsea pipelines. The lure document was blurred in order to deceive targets into clicking “Enable Content” thereby triggering the execution of the embedded macro. -Screenshot 2026-05-03 at 17-16-58 Operation Olalampo Inside MuddyWater’s Latest Campaign Group-IB Blog +word-image-353730-175304-5-1177x700 The attack group delivered a malicious Excel and Word files designed to mimic the target’s internal financial records. The lure appeared as a legitimate spreadsheet containing payment details and cash flow projections.