logo

BINDCLOAK Steals Windows User and Process Tokens to Run Malware With Higher Privileges

ID: b7b73729-9a2a-5a73-8fd4-1c8d81883d61

STIX ID: report--b7b73729-9a2a-5a73-8fd4-1c8d81883d61

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Tushar Subhra Dutta

...
...

Zscaler analysts uncovered BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor used by an East Asia-linked espionage campaign targeting Middle Eastern government and energy organizations; the malware abuses Windows access tokens to escalate privileges, reflectively loads DLLs into memory, communicates with TLS-protected C2 servers, and is part of a multi-stage chain (ISO -> TELESHIM -> MIXEDKEY -> BINDCLOAK) with several published IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.