logo

New Zardoor backdoor used in long-term cyber espionage operation targeting an Islamic organization

ID: 9500c76f-39bb-5377-9632-a7166f2db03e

STIX ID: report--9500c76f-39bb-5377-9632-a7166f2db03e

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2024-02-08

Date Updated: 2026-04-27

Author: Cisco Talos

...
...

Cisco Talos identified an ongoing, stealthy espionage campaign against an Islamic non-profit in Saudi Arabia that uses a novel backdoor family called Zardoor (zar32.dll, zor32.dll) deployed via MSDTC DLL side-loading; the actor leverages living-off-the-land binaries and customized reverse-proxy tools (FRP, sSocks, Venom) to establish C2, maintain persistence, perform lateral movement and exfiltrate data roughly twice a month, with detailed IOCs and MITRE ATT&CK mappings provided but no confident attribution to a known group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.