logo

Islamic Nonprofit Infiltrated for 3 Years With Silent Backdoor

ID: d1d9bf08-586a-5737-ae10-4920f9254e8c

STIX ID: report--d1d9bf08-586a-5737-ae10-4920f9254e8c

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-02-13

Date Updated: 2026-04-21

Author: John Leyden, Contributing Writer

...
...

Cisco Talos researchers uncovered a stealthy, long-running espionage campaign (active since March 2021) targeting a Saudi Arabian charity using a custom backdoor named Zardoor. The attackers established persistent C2 via modified open-source reverse-proxy tools (FRP, Socks custom server, Venom), used WMI for lateral movement, and exfiltrated encrypted data approximately twice monthly; Cisco published detections and IOCs to help defenders hunt and remediate infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.