logo

Targeted Attack on Middle East Govts (Part 2)

ID: 91d85032-54a1-577a-b040-836140b3a7da

STIX ID: report--91d85032-54a1-577a-b040-836140b3a7da

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

...
...

BINDCLOAK is a 64-bit modular backdoor described in this technical analysis that enumerates host info, generates a 4-byte victim ID, and implements a TLS-over-TCP C2 with a 28-byte header message format, zlib compression and a dual-pass rolling-XOR encryption. It supports built-in modules and dynamically loaded plugin DLLs (reflectively loaded with RWX memory) and exposes commands for token collection/elevation, module management, and execution persistence techniques; the report includes a sample MD5 and detailed protocol/loader behavior useful for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.