Date: 08/04/2026
Severity: High
Summary
Part 2 of this analysis focuses on new tools used by an East Asia-linked threat actor targeting government organizations in the Middle East. Following ThreatLabz’s Part 1 coverage of the TELESHIM backdoor and MIXEDKEY loader, Kaspersky reported a related campaign. This installment provides a detailed technical analysis of BINDCLOAK, a newly discovered modular stage-three backdoor. Researchers identified significant code similarities between BINDCLOAK and the previously known OctLurk malware. Shared command-and-control (C2) infrastructure further links the two malware families to the same threat activity. ThreatLabz assesses with high confidence that BINDCLOAK is a variant of OctLurk and examines its previously undocumented C2 communication channel.
Indicators of Compromise (IOC) List
Domains/URLs | cert.hypersnet.com |
Hash | 7a14a99d70d42d3f7bf72f843185fc07
577b1cc894636f4ac5ad670b0079b9b7ade137c3
3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "cert.hypersnet.com" or url like "cert.hypersnet.com" or siteurl like "cert.hypersnet.com" |
Detection Query 2 : | md5hash In ("7a14a99d70d42d3f7bf72f843185fc07")
|
Detection Query 3 : | sha1hash In ("577b1cc894636f4ac5ad670b0079b9b7ade137c3")
|
Detection Query 4 : | sha256hash In ("3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d")
|
Reference:
https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-2