New Zardoor backdoor used in long-term cyber espionage operation targeting an Islamic organization
ID: 9500c76f-39bb-5377-9632-a7166f2db03e
STIX ID: report--9500c76f-39bb-5377-9632-a7166f2db03e
Feed Name: Cisco Talos
Cisco Talos identified an ongoing, stealthy espionage campaign against an Islamic non-profit in Saudi Arabia that uses a novel backdoor family called Zardoor (zar32.dll, zor32.dll) deployed via MSDTC DLL side-loading; the actor leverages living-off-the-land binaries and customized reverse-proxy tools (FRP, sSocks, Venom) to establish C2, maintain persistence, perform lateral movement and exfiltrate data roughly twice a month, with detailed IOCs and MITRE ATT&CK mappings provided but no confident attribution to a known group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
