logo

Technical Analysis of MLTBackdoor

ID: 6f655c26-fa42-5567-9626-4b25f7c02eec

STIX ID: report--6f655c26-fa42-5567-9626-4b25f7c02eec

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-10

Author: ThreatLabz (Zscaler)

...
...

In May 2026 Zscaler ThreatLabz published a technical analysis of MLTBackdoor, a heavily obfuscated Windows backdoor likely used to support ransomware operations; the report covers the ClickFix-based multi-stage infection, RC4-encrypted staged payloads and DLL sideloading, extensive MBA and control-flow flattening obfuscation, API hashing and indirect system calls, multiple anti-analysis checks, a BOF loader for expanding capabilities, and a custom ECDH + AES-256-GCM encrypted protocol over TLS with a date-based DGA for fallback; it also includes sample hashes, C2 domains, and behavioral indicators for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.