BINDCLOAK is a previously undocumented modular 64-bit Windows backdoor used as a late-stage implant in a multi-stage cyberespionage campaign targeting government entities in the Middle East, including the energy sector. It has been assessed with high confidence as a variant of the OctLurk backdoor based on code similarities and overlapping command-and-control infrastructure. The malware is deployed after initial compromise by the MIXEDKEY loader, which decrypts and reflectively loads the implant during post-compromise operations.
BINDCLOAK is designed for stealthy persistence and operator-controlled post-exploitation. It communicates with its command server over TLS on top of TCP using a custom routed protocol with compressed and doubly XOR-encrypted messages. On initial beaconing it collects host reconnaissance data such as operating system version, computer name, username, hostname, local IP information, and local time. The implant contains core command-and-control and command modules and supports delivery of additional plugin DLLs from the server.
A notable feature of BINDCLOAK is abuse of Windows access tokens to execute modules under more privileged security contexts. It can attempt authentication with supplied credentials to obtain user tokens, enumerate running processes and associated token properties, duplicate selected tokens, and impersonate logged-on users to launch modules with elevated rights. This provides a practical privilege-escalation mechanism without relying solely on software exploits. The malware also supports in-memory plugin loading and module replacement, allowing operators to extend or swap functionality without reinstalling the full implant.
BINDCLOAK includes defense-evasion measures intended to reduce endpoint visibility. Additional modules are loaded directly into memory, executable memory is allocated for plugin handling, and import resolution is performed in a way intended to make suspicious DLL loading behavior less obvious to security tools. Observed tradecraft and infrastructure overlap link BINDCLOAK to an East Asia-linked threat actor previously associated with operations in Central Asia and later observed expanding activity into the Middle East.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Security teams should investigate unknown ISO files, unusual scheduled tasks, DLLs placed beside trusted executables, and processes launching under unexpected user contexts.
This installment provides a detailed technical analysis of BINDCLOAK, a newly discovered modular stage-three backdoor.
The campaign targeted government entities in the Middle East, with a particular focus on the energy sector. Attackers used a multi-stage chain that began with an ISO file and legitimate-looking Windows components before delivering TELESHIM, MIXEDKEY, and finally BINDCLOAK.
Security teams should investigate unknown ISO files, unusual scheduled tasks, DLLs placed beside trusted executables, and processes launching under unexpected user contexts.
Similar concerns apply when attackers abuse legitimate processes for malicious DLL payload injection, which can hide code behind trusted Windows activity.
Instead of relying only on a software flaw, BINDCLOAK collects available tokens and uses them to launch its modules with the rights of a more privileged account.
It can attempt to log in with supplied credentials, retain a successful user token, and later use that token to start a selected module.
The malware uses heavy code obfuscation, environmental keying, and Telegram API-based command-and-control (C2) communications to evade analysis, blend with legitimate traffic, and maintain persistent access on compromised systems.
Similar concerns apply when attackers abuse legitimate processes for malicious DLL payload injection, which can hide code behind trusted Windows activity.
Instead of relying only on a software flaw, BINDCLOAK collects available tokens and uses them to launch its modules with the rights of a more privileged account.
It can attempt to log in with supplied credentials, retain a successful user token, and later use that token to start a selected module.
That allows the operator to select a process token that may offer stronger access, then duplicate it and start a BINDCLOAK module in that security context.
BINDCLOAK can abuse user tokens collected from authenticated with provided credentials
The threat actor leveraged environmental keying by encrypting BINDCLOAK using a decryption key derived from the infected machine’s volume serial number.
ThreatLabz noted that it identified post-compromise activity from the C2 operator, such as system, user, and network reconnaissance commands
ThreatLabz noted that it identified post-compromise activity from the C2 operator, such as system, user, and network reconnaissance commands
The backdoor also examines active processes for their IDs, account details, and token permissions.
This installment provides a detailed technical analysis of BINDCLOAK, a newly discovered modular stage-three backdoor... ThreatLabz assesses with high confidence that BINDCLOAK is a variant of OctLurk and examines its previously undocumented C2 communication channel.
BINDCLOAK communicates with its command server through TLS over TCP, using a custom message-routing system.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly discovered modular stage-three backdoor used in a targeted campaign against government organizations in the Middle East.
A previously undocumented 64-bit Windows modular backdoor written in C. It is deployed post-compromise, steals and abuses Windows user and process access tokens for privilege escalation, loads DLL modules directly into memory, communicates with C2 over TLS/TCP, and supports stopping, removing, and replacing modules.
A previously undocumented 64-bit modular Windows backdoor written in C++ that is decrypted and reflectively loaded by MIXEDKEY, uses TLS-over-TCP C2 with a complex message routing mechanism, supports plugin DLL modules, and includes EDR-evasion techniques for API calls from unbacked executable memory.
A previously undocumented 64-bit modular Windows backdoor written in C++ and deployed during post-compromise activity. It is decrypted and reflectively loaded by MIXEDKEY, uses TLS-over-TCP C2 with a complex message routing mechanism, supports plugin DLL modules, collects host and process/token information, can impersonate tokens for privilege escalation, and includes EDR-evasion techniques for API calls from unbacked executable memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.