Threat reportMalwareTL-2026-1858

BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for Privilege Escalation

highACTIVE

BINDCLOAK: Previously Undocumented 64-bit Modular Windows (TL-2026-1858), also tracked as Operation BINDCLOAK, is a high-severity malware campaign, first published 2026-08-04. It has no confirmed attribution, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1003, T1027, T1049), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1858

Threat ID
TL-2026-1858
Also known as
Operation BINDCLOAK, Middle East Energy Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
ESPIONAGE
Target sectors
government administration, energy, health, education, police - law enforcement
Target regions
Middle East, 143 - Central Asia
Detection rules
9
Indicators of compromise
20

Malware and tooling in BINDCLOAK: Previously Undocumented 64-bit Modular Windows

Malware and tooling: PlugX

How BINDCLOAK: Previously Undocumented 64-bit Modular Windows works

BINDCLOAK is a previously undocumented 64-bit modular Windows backdoor (C++) that steals user and process tokens to escalate privileges via ImpersonateLoggedOnUser, DuplicateTokenEx, and LogonUserW. It is deployed as the stage-3 payload in an ISO-based multi-stage chain (TELESHIM > MIXEDKEY > BINDCLOAK) targeting Middle Eastern government entities with a focus on the energy sector. Zscaler ThreatLabz assesses with high confidence that BINDCLOAK is a variant of the OctLurk backdoor operated by an East Asia-linked espionage actor that previously targeted Central Asia.

BINDCLOAK is a previously undocumented 64-bit modular Windows backdoor written in C++ that delivers privilege escalation through token theft rather than traditional exploit-based elevation. The malware is deployed as the final stage in a three-stage attack chain initiated through diplomatic-themed ISO file lures targeting Middle Eastern government entities, particularly in the energy sector.

The infection chain begins when a target opens an ISO file containing government-themed filenames such as 'Cooperation protocol for the exploration of petroleum and gas (English).img' or 'Agreement on the Establishment of Common Border Offices (English).img'. The ISO contains a legitimate ASUSTek RegSchdTask.exe binary alongside a malicious AsTaskSched.dll that is DLL side-loaded to execute TELESHIM, a 32-bit C++ backdoor that abuses the Telegram Bot API for command-and-control. TELESHIM performs extensive reconnaissance (net user, tasklist, ipconfig, netstat), uses heavy obfuscation (CFF/MBA/opaque predicates), and implements anti-analysis measures including CPUID-based hypervisor detection and a 1 GB I/O stress test designed to stall sandbox execution. It persists via a scheduled task named 'shimgen' running every 6 minutes.

Post-compromise, the threat actor deploys a legitimate GoPro binary alongside pthreadVC2.dll, which is actually MIXEDKEY — a 64-bit reflective loader. MIXEDKEY uses two-layer XOR decryption with environmental keying derived from the victim's C:\ volume serial number, ensuring the payload only decrypts on the intended target. MIXEDKEY reflectively loads the decrypted BINDCLOAK DLL into memory and invokes its curl_easy_escape export.

BINDCLOAK is a modular implant with two built-in modules (C2 module 0x1010 and Command module 0x1020) and a plugin architecture supporting reflective loading of additional DLLs delivered from the C2 server. Its core innovation is token-based privilege escalation: the Commands module (0x1020) implements COLLECT_USER_TOKEN (calls LogonUserW with supplied credentials to collect user token handles), GET_STATUS (enumerates processes via WTSEnumerateProcessesW with OpenProcessToken to inspect TOKEN_QUERY/TOKEN_DUPLICATE/TOKEN_ASSIGN_PRIMARY flags), START_MODULE_WITH_USER_TOKEN (calls DuplicateTokenEx with TOKEN_ASSIGN_PRIMARY to launch modules under a higher-privileged token), and START_MODULE_WITH_PROCESS_TOKEN (similar but using process tokens from running processes). This token abuse blends into normal Windows behavior, evading detection by appearing as legitimate impersonation.

BINDCLOAK communicates via TLS over TCP with a custom message-routing protocol. All messages use a 28-byte header followed by two variable-sized blob payloads. Beacon messages collect OS version (OSVERSIONINFOEX), computer name (GetComputerNameW), username (GetUserNameW), hostname (gethostname), local IP (GetAddrInfoW), and local time (GetLocalTime). Messages are triple-encrypted: zlib compression, followed by a 105-byte rolling XOR key constructed as a stack string, followed by an 83-byte random XOR key with random padding (14—41 bytes). The C2 infrastructure reuses an SSL certificate (serial 59fe1ef7707fe497d89f34505222862f, CN 107.175.172.40) across both BINDCLOAK (cert.hypersnet.com) and OctLurk (about.blsouqs.com) domains.

The plugin loader allocates RWX memory via VirtualAlloc, uses RtlQueueWorkItem to call LoadLibraryW for import resolution (evading EDR detection of LoadLibraryW calls from unbacked executable memory), and modifies PE headers to hinder static detection. Plugin module DLLs must export ins_ctl_db and oct_lk_col functions.

Zscaler ThreatLabz assesses with high confidence that BINDCLOAK is a variant of the OctLurk backdoor based on identical beacon message structures, the same encryption algorithm (zlib + double XOR), high XOR key similarity, shared infrastructure (SSL certificate reuse, Tucows registrar, Njalla name servers, ASN 14956), and operational overlaps (the actor pinged both BINDCLOAK and OctLurk C2 servers during post-compromise activity). Kaspersky GReAT separately documented OctLurk and a related backdoor (SilkLurk) targeting Central Asian governments and Syrian entities starting January 2025, attributed with medium confidence to a Chinese-speaking threat actor. The July 2026 campaign marks a notable geographic and sectoral expansion from Central Asian government targets to Middle Eastern energy sector entities.

MITRE ATT&CK techniques used in TL-2026-1858

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials

Defense Evasion

T1027 Obfuscated Files or Information; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading

Discovery

T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery

Persistence

T1053 Scheduled Task/Job

Collection

T1056 Input Capture; T1113 Screen Capture; T1119 Automated Collection

Command and Control

T1095 Non-Application Layer Protocol; T1132 Data Encoding; T1573 Encrypted Channel

collection

T1560 Archive Collected Data

Initial Access

T1566 Phishing

stealth

T1574 Hijack Execution Flow

Affected products and versions in BINDCLOAK: Previously Undocumented 64-bit Modular Windows

  • Microsoft — Windows
    Vulnerable versions: All versions supporting ImpersonateLoggedOnUser

Remediation for BINDCLOAK: Previously Undocumented 64-bit Modular Windows

Immediate actions

  • Block C2 domains cert.hypersnet.com, about.blsouqs.com, ssl.blsouqs.com, contacts.ftabnews.com at perimeter
  • Block IP 107.175.172.40 at firewall
  • Deploy YARA signatures for BINDCLOAK (MD5 7a14a99d70d42d3f7bf72f843185fc07), TELESHIM, and MIXEDKEY hashes
  • Scan for scheduled tasks named 'shimgen' and 'Feedback' on Windows endpoints

Workarounds

  • Restrict execution of ISO files from email/downloads to administrative approval
  • Enable Windows Defender Attack Surface Reduction rules for DLL side-loading
  • Audit scheduled tasks for creation of unrecognized tasks with frequent intervals

Longer-term hardening

  • Monitor for abnormal token usage (ImpersonateLoggedOnUser, DuplicateTokenEx calls from non-system processes)
  • Monitor for RtlQueueWorkItem calling LoadLibraryW from unbacked memory regions
  • Hunt for unscheduled TLS connections to Tucows/Njalla-registered domains on ASN 14956
  • Monitor Telegram Bot API traffic from non-browser processes
  • Implement ISO file execution telemetry and DLL side-loading detection

Timeline of BINDCLOAK: Previously Undocumented 64-bit Modular Windows

  • Threat actor registers C2 infrastructure including about.blsouqs.com and ssl.blsouqs.com via Tucows registrar with Njalla name servers on ASN 14956
  • OctLurk/SilkLurk operation begins targeting Central Asian governments (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan) and Syria, as documented by Kaspersky GReAT
  • Diplomatic-themed ISO lures deployed targeting Middle Eastern energy sector entities, including petroleum and border-agreement themed filenames
  • Current TELESHIM variant compiled (July 2026); two older variants previously compiled in 2025
  • First observed post-compromise command execution in the Middle East campaign via TELESHIM backdoor, with reconnaissance and deployment of MIXEDKEY/BINDCLOAK
  • Last day of observed post-compromise activity; actor verified connectivity to BINDCLOAK C2 (cert.hypersnet.com) and OctLurk C2 servers via ping commands
  • Zscaler ThreatLabz publishes two-part analysis of the campaign; Kaspersky GReAT publishes OctLurk/SilkLurk report; Cybersecurity News publishes BINDCLOAK coverage

Sources cited for BINDCLOAK: Previously Undocumented 64-bit Modular Windows

Detection coverage for TL-2026-1858

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1858 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats