As cited
Copy frozen at (site build).
threat intel
Targeted Attack on Government Entities in the Middle East | Part 2
Zscaler ThreatLabz has disclosed BINDCLOAK, a new 64-bit modular Windows backdoor deployed against government entities in the Middle East. The malware uses a complex message routing mechanism for command-and-control communication and employs endpoint detection and response (EDR) evasion techniques including reflective DLL loading with token manipulation for privilege escalation. Attribution links the backdoor to the OctLurk threat actor through code similarities, shared command-and-control infrastructure, and domain registrar patterns, marking an expansion from Central Asia operations.
Why it matters: Middle East government and energy sector organizations face immediate risk from this backdoor's modular architecture and token-based privilege escalation; practitioners should monitor for BINDCLOAK indicators, the C2 domain cert.hypersnet[.]com, and the referenced file hashes to detect post-compromise activity and plugin deployment.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Targeted Attack on Government Entities in the Middle East | Part 2
Zscaler ThreatLabz has disclosed BINDCLOAK, a new 64-bit modular Windows backdoor deployed against government entities in the Middle East. The malware uses a complex message routing mechanism for command-and-control communication and employs endpoint detection and response (EDR) evasion techniques including reflective DLL loading with token manipulation for privilege escalation. Attribution links the backdoor to the OctLurk threat actor through code similarities, shared command-and-control infrastructure, and domain registrar patterns, marking an expansion from Central Asia operations.
Why it matters: Middle East government and energy sector organizations face immediate risk from this backdoor's modular architecture and token-based privilege escalation; practitioners should monitor for BINDCLOAK indicators, the C2 domain cert.hypersnet[.]com, and the referenced file hashes to detect post-compromise activity and plugin deployment.
- Source published
- First seen by Cybersecurity Tracker