Part 1 covered a multi-stage infection chain that begins with an ISO file delivering previously undocumented tooling: TELESHIM and MIXEDKEY. In Part 2, they analyze BINDCLOAK and highlight code overlaps and shared C2 infrastructure with OctLurk.
After ThreatLabz published
Part 1 on the TELESHIM backdoor and MIXEDKEY loader,
Kaspersky highlighted a related campaign in recent reporting. Building upon our initial findings, Part 2 dives into a detailed technical analysis of
BINDCLOAK, a new modular stage 3 backdoor uncovered during our investigation. As detailed later in our threat attribution section, key code similarities between BINDCLOAK and OctLurk as well as shared command-and-control (C2) infrastructure directly connect the threat actor behind OctLurk to the campaign we describe in this two-part blog series.
ThreatLabz assesses with high-confidence that BINDCLOAK is a variant of OctLurk. In this blog, we analyze BINDCLOAK’s previously undocumented C2 communication channel.
ThreatLabz examines a targeted attack against Middle East governments using a multi-stage attack chain with new tooling that we named BINDCLOAK.
www.zscaler.com
Key Takeaways
- BINDCLOAK is a previously undocumented and new 64-bit modular Windows backdoor written in C++ that was deployed on victims' machines during post-compromise activity.
- BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY in a multi-stage attack chain targeting government entities in the Middle East.
- A complex message routing mechanism is used by BINDCLOAK to manage the C2 communication channel with the C2 server.
- BINDCLOAK implements endpoint detection and response (EDR) evasion techniques to prevent detection of API calls from unbacked executable memory regions.