CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Targeted Attack on Government Entities in the Middle East | Part 2

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6240

As cited

Copy frozen at (site build).

threat intel

Targeted Attack on Government Entities in the Middle East | Part 2

Zscaler ThreatLabz has disclosed BINDCLOAK, a new 64-bit modular Windows backdoor deployed against government entities in the Middle East. The malware uses a complex message routing mechanism for command-and-control communication and employs endpoint detection and response (EDR) evasion techniques including reflective DLL loading with token manipulation for privilege escalation. Attribution links the backdoor to the OctLurk threat actor through code similarities, shared command-and-control infrastructure, and domain registrar patterns, marking an expansion from Central Asia operations.

Why it matters: Middle East government and energy sector organizations face immediate risk from this backdoor's modular architecture and token-based privilege escalation; practitioners should monitor for BINDCLOAK indicators, the C2 domain cert.hypersnet[.]com, and the referenced file hashes to detect post-compromise activity and plugin deployment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Targeted Attack on Government Entities in the Middle East | Part 2

Zscaler ThreatLabz has disclosed BINDCLOAK, a new 64-bit modular Windows backdoor deployed against government entities in the Middle East. The malware uses a complex message routing mechanism for command-and-control communication and employs endpoint detection and response (EDR) evasion techniques including reflective DLL loading with token manipulation for privilege escalation. Attribution links the backdoor to the OctLurk threat actor through code similarities, shared command-and-control infrastructure, and domain registrar patterns, marking an expansion from Central Asia operations.

Why it matters: Middle East government and energy sector organizations face immediate risk from this backdoor's modular architecture and token-based privilege escalation; practitioners should monitor for BINDCLOAK indicators, the C2 domain cert.hypersnet[.]com, and the referenced file hashes to detect post-compromise activity and plugin deployment.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary