Targeted Attack on Middle East Govts (Part 1)
ID: 8ee738c1-6ceb-5449-9668-446aeebd92d1
STIX ID: report--8ee738c1-6ceb-5449-9668-446aeebd92d1
Feed Name: Zscaler Security Research Blog
ThreatLabz provides a technical analysis of a multi-stage Windows malware campaign that begins with an ASUSTek executable sideloading a malicious DLL to deploy TELESHIM (32-bit backdoor), which stages and persists via scheduled tasks and uses the Telegram API for C2; a 64-bit loader named MIXEDKEY performs volume-locked decryption and reflective loading of the final payload, BINDCLOAK, which beacons to cert.hypersnet.com. The report details string decryption methods, anti-analysis techniques (I/O stress, CPUID hypervisor checks, WMI RAM checks), staging paths and filenames, observed post-compromise commands, and provides indicators and behavioral TTPs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
