MuddyWater / Boggy Serpens (Operation Olalampo) Consolidated Threat Hunt

This rule performs a comprehensive hunt for activities associated with the MuddyWater (also known as Boggy Serpens) threat group, specifically relating to their 'Operation Olalampo' campaign. It monitors for spearphishing artifacts (lure documents and attachments), execution of specific malware and drop artifacts, the use of LOLBins by Office applications, unauthorized remote access via AnyDesk, Telegram-based C2 communication, and persistence mechanisms such as registry run keys and specific file extensions (.wdlp).