Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Targeted Attack on Government Entities in the Middle East | Part 2

contacts.ftabnews.com

TLP:CLEAR
Active

Domain

Description

A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Targeted Attack on Government Entities in the Middle East | Part 2
Pattern Type
STIX
Confidence
75%
Valid From
Aug 4, 2026 10:00
Total Sightings
0
Added
Aug 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of contacts.ftabnews.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.