Zscaler details BINDCLOAK, a new 64-bit modular Windows backdoor that appears to be a variant of OctLurk and was delivered through MIXEDKEY in a multi-stage attack against government entities in the Middle East. The report also links the campaign to shared C2 infrastructure, reflective DLL loading, token abuse, and encrypted TLS-over-TCP communications used by the same threat actor behind OctLurk. #BINDCLOAK #OctLurk #MIXEDKEY #TELESHIM #cert.hypersnet.com #about.blsouqs.com #ftabnews.com
Keypoints
- BINDCLOAK is a newly identified 64-bit modular Windows backdoor written in C++.
- ThreatLabz assesses with high confidence that BINDCLOAK is a variant of OctLurk.
- The malware was deployed through a multi-stage chain involving MIXEDKEY and targeted government entities in the Middle East.
- BINDCLOAK uses a complex message routing design and encrypted C2 communications over TLS/TCP.
- The backdoor supports module management, plugin delivery, token collection, and process discovery.
- It includes EDR-evasion and stealth mechanisms such as reflective loading and API execution from unbacked memory regions.
- Infrastructure overlap links the campaign to OctLurk-related domains and shared SSL certificate reuse.
MITRE Techniques
- [T1134.001 ] Token Impersonation/Theft – BINDCLOAK can escalate privileges for modules by abusing collected user and process tokens (‘can escalate privileges for modules by abusing collected user and process tokens’).
- [T1134.003 ] Make and Impersonate Token – BINDCLOAK abuses user tokens collected after authentication to start modules with elevated context (‘abuse user tokens collected from authenticated with provided credentials’).
- [T1620 ] Reflective Code Loading – BINDCLOAK reflectively loads plugin DLLs into memory to execute them stealthily (‘reflectively loads plugin module DLLs’).
- [T1057 ] Process Discovery – BINDCLOAK enumerates running processes and collects associated user and token details (‘collects information about running processes and associated user and token’).
- [T1132.002 ] Non-Standard Encoding – BINDCLOAK uses two layers of XOR plus zlib compression to encode C2 traffic (‘uses two layers of XOR encoding for C2 communication’).
- [T1095 ] Non-Application Layer Protocol – BINDCLOAK communicates with its C2 server using TLS over TCP (‘uses TLS over TCP for C2 communication’).
Indicators of Compromise
- [MD5 hash ] BINDCLOAK sample analyzed in the report – 7a14a99d70d42d3f7bf72f843185fc07
- [SHA1 hash ] Additional BINDCLOAK file indicator – 577b1cc894636f4ac5ad670b0079b9b7ade137c3
- [SHA256 hash ] Additional BINDCLOAK file indicator – 3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d
- [Domain ] C2 infrastructure associated with BINDCLOAK – cert.hypersnet[.]com
- [Domain ] Related OctLurk-linked infrastructure and post-compromise activity – ssl.blsouqs[.]com, about.blsouqs[.]com
- [Domain ] Additional suspected threat actor infrastructure – contacts.ftabnews[.]com, ftabnews[.]com
- [SSL certificate serial number ] Certificate reused across BINDCLOAK and OctLurk infrastructure – 59fe1ef7707fe497d89f34505222862f
- [IP address ] Common Name in reused SSL certificate – 107.175.172[.]40