logo

Technical Analysis of MLTBackdoor

ID: 63131f86-d7cc-51e8-b281-b311e98d9488

STIX ID: report--63131f86-d7cc-51e8-b281-b311e98d9488

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2026-06-26

Date Updated: 2026-07-04

...
...

The report provides a technical analysis of MLTBackdoor, a sophisticated Windows backdoor observed distributed via a ClickFix lure and a date-based DGA; it details the full infection chain, extensive LLVM-based obfuscation (MBA, CFF, stack-built strings), indirect system-call trampolines, DJB2 API hashing, anti-analysis checks, a BOF loader compatible with Cobalt Strike imports, and a custom AES-256-GCM-over-TLS protocol using ECDH (P-256) with fixed path and User-Agent to blend in with legitimate traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.