MIXEDKEY is a 64-bit Windows reflective loader used in a multi-stage cyberespionage campaign attributed with moderate-to-high confidence to an East Asia-linked threat actor targeting government entities in the Middle East, including the energy sector. It is deployed after earlier compromise stages and is responsible for decrypting a protected next-stage payload and loading it directly into memory. In observed intrusions, MIXEDKEY delivered the BINDCLOAK backdoor following earlier use of the TELESHIM backdoor.
The loader is designed to hinder analysis through heavy obfuscation, including mixed boolean arithmetic and runtime string construction. Its payload decryption uses two XOR layers, one of which is derived from the victim machine’s volume serial number, indicating environmental keying intended to restrict successful execution to intended hosts. After decryption, MIXEDKEY reflectively loads the final payload rather than relying on standard disk-backed module loading, supporting stealth during post-compromise activity.
MIXEDKEY has been observed in a DLL sideloading chain involving legitimate software components, where a malicious DLL is loaded by a benign executable. Its primary role is execution of the final implant rather than persistence or command-and-control. In the documented campaign, it served as the transition stage between initial foothold malware and the modular BINDCLOAK backdoor used for deeper access inside victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Security teams should investigate unknown ISO files, unusual scheduled tasks, DLLs placed beside trusted executables, and processes launching under unexpected user contexts.
The campaign targeted government entities in the Middle East, with a particular focus on the energy sector. Attackers used a multi-stage chain that began with an ISO file and legitimate-looking Windows components before delivering TELESHIM, MIXEDKEY, and finally BINDCLOAK.
Both TELESHIM and MIXEDKEY have been found to rely on heavy code obfuscation techniques, including string encryption, control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates to deter reverse engineering efforts.
The final payload is encrypted using two layers of XOR encryption... MIXEDKEY decrypts the payload and reflectively loads it.
The threat actor leveraged environmental keying by encrypting BINDCLOAK using a decryption key derived from the infected machine’s volume serial number.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader discussed in prior coverage as part of the related threat activity.
A post-compromise malware component used to decrypt and reflectively load BINDCLOAK.
A loader used earlier in the attack chain to decrypt and reflectively load BINDCLOAK on victim machines.
A loader used in the multi-stage attack chain to decrypt and reflectively load BINDCLOAK.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.