logo

Stealthy Zardoor Backdoor Targets Saudi Islamic Charity Organization

ID: 27376e5e-2980-51ed-b853-7ce2ddbfefcb

STIX ID: report--27376e5e-2980-51ed-b853-7ce2ddbfefcb

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco Talos uncovered a stealthy cyber-espionage campaign active since at least March 2021 that targeted an unnamed Islamic non-profit in Saudi Arabia and deployed a novel backdoor family dubbed "Zardoor." The intrusion chain uses a dropper to install a malicious DLL that deploys two modules for persistence and privileged execution, leverages living-off-the-land binaries and open-source reverse-proxy tools (FRP, sSocks, Venom) for C2, and uses WMI for lateral movement; the actor performed periodic data exfiltration (about twice monthly) and is assessed as an advanced threat, though only one victim has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.