Targeted Attack on Government Entities in the Middle East - Part 2

    Date: 08/04/2026

    Severity: High

    Summary

    Part 2 of this analysis focuses on new tools used by an East Asia-linked threat actor targeting government organizations in the Middle East. Following ThreatLabz’s Part 1 coverage of the TELESHIM backdoor and MIXEDKEY loader, Kaspersky reported a related campaign. This installment provides a detailed technical analysis of BINDCLOAK, a newly discovered modular stage-three backdoor. Researchers identified significant code similarities between BINDCLOAK and the previously known OctLurk malware. Shared command-and-control (C2) infrastructure further links the two malware families to the same threat activity. ThreatLabz assesses with high confidence that BINDCLOAK is a variant of OctLurk and examines its previously undocumented C2 communication channel.

    Indicators of Compromise (IOC) List

    Domains/URLs

    cert.hypersnet.com

    Hash  

    7a14a99d70d42d3f7bf72f843185fc07

    577b1cc894636f4ac5ad670b0079b9b7ade137c3

    3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "cert.hypersnet.com" or url like "cert.hypersnet.com" or siteurl like "cert.hypersnet.com"

    Detection Query 2 :

    md5hash In ("7a14a99d70d42d3f7bf72f843185fc07")

    Detection Query 3 :

    sha1hash In ("577b1cc894636f4ac5ad670b0079b9b7ade137c3")

    Detection Query 4 :

    sha256hash In ("3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d")

    Reference:  

    https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-2           


    Tags

    MalwareThreat ActorThe Middle EastGovernment Services and FacilitiesBackdoorLoader

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags