Threat reportMalwareTL-2026-1858
BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for Privilege Escalation
BINDCLOAK: Previously Undocumented 64-bit Modular Windows (TL-2026-1858), also tracked as Operation BINDCLOAK, is a high-severity malware campaign, first published 2026-08-04. It has no confirmed attribution, affects Microsoft Windows, maps to 19 MITRE ATT&CK techniques (T1003, T1027, T1049), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1858
- Threat ID
- TL-2026-1858
- Also known as
- Operation BINDCLOAK, Middle East Energy Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- government administration, energy, health, education, police - law enforcement
- Target regions
- Middle East, 143 - Central Asia
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in BINDCLOAK: Previously Undocumented 64-bit Modular Windows
Malware and tooling: PlugX
How BINDCLOAK: Previously Undocumented 64-bit Modular Windows works
BINDCLOAK is a previously undocumented 64-bit modular Windows backdoor (C++) that steals user and process tokens to escalate privileges via ImpersonateLoggedOnUser, DuplicateTokenEx, and LogonUserW. It is deployed as the stage-3 payload in an ISO-based multi-stage chain (TELESHIM > MIXEDKEY > BINDCLOAK) targeting Middle Eastern government entities with a focus on the energy sector. Zscaler ThreatLabz assesses with high confidence that BINDCLOAK is a variant of the OctLurk backdoor operated by an East Asia-linked espionage actor that previously targeted Central Asia.
BINDCLOAK is a previously undocumented 64-bit modular Windows backdoor written in C++ that delivers privilege escalation through token theft rather than traditional exploit-based elevation. The malware is deployed as the final stage in a three-stage attack chain initiated through diplomatic-themed ISO file lures targeting Middle Eastern government entities, particularly in the energy sector.
The infection chain begins when a target opens an ISO file containing government-themed filenames such as 'Cooperation protocol for the exploration of petroleum and gas (English).img' or 'Agreement on the Establishment of Common Border Offices (English).img'. The ISO contains a legitimate ASUSTek RegSchdTask.exe binary alongside a malicious AsTaskSched.dll that is DLL side-loaded to execute TELESHIM, a 32-bit C++ backdoor that abuses the Telegram Bot API for command-and-control. TELESHIM performs extensive reconnaissance (net user, tasklist, ipconfig, netstat), uses heavy obfuscation (CFF/MBA/opaque predicates), and implements anti-analysis measures including CPUID-based hypervisor detection and a 1 GB I/O stress test designed to stall sandbox execution. It persists via a scheduled task named 'shimgen' running every 6 minutes.
Post-compromise, the threat actor deploys a legitimate GoPro binary alongside pthreadVC2.dll, which is actually MIXEDKEY — a 64-bit reflective loader. MIXEDKEY uses two-layer XOR decryption with environmental keying derived from the victim's C:\ volume serial number, ensuring the payload only decrypts on the intended target. MIXEDKEY reflectively loads the decrypted BINDCLOAK DLL into memory and invokes its curl_easy_escape export.
BINDCLOAK is a modular implant with two built-in modules (C2 module 0x1010 and Command module 0x1020) and a plugin architecture supporting reflective loading of additional DLLs delivered from the C2 server. Its core innovation is token-based privilege escalation: the Commands module (0x1020) implements COLLECT_USER_TOKEN (calls LogonUserW with supplied credentials to collect user token handles), GET_STATUS (enumerates processes via WTSEnumerateProcessesW with OpenProcessToken to inspect TOKEN_QUERY/TOKEN_DUPLICATE/TOKEN_ASSIGN_PRIMARY flags), START_MODULE_WITH_USER_TOKEN (calls DuplicateTokenEx with TOKEN_ASSIGN_PRIMARY to launch modules under a higher-privileged token), and START_MODULE_WITH_PROCESS_TOKEN (similar but using process tokens from running processes). This token abuse blends into normal Windows behavior, evading detection by appearing as legitimate impersonation.
BINDCLOAK communicates via TLS over TCP with a custom message-routing protocol. All messages use a 28-byte header followed by two variable-sized blob payloads. Beacon messages collect OS version (OSVERSIONINFOEX), computer name (GetComputerNameW), username (GetUserNameW), hostname (gethostname), local IP (GetAddrInfoW), and local time (GetLocalTime). Messages are triple-encrypted: zlib compression, followed by a 105-byte rolling XOR key constructed as a stack string, followed by an 83-byte random XOR key with random padding (14—41 bytes). The C2 infrastructure reuses an SSL certificate (serial 59fe1ef7707fe497d89f34505222862f, CN 107.175.172.40) across both BINDCLOAK (cert.hypersnet.com) and OctLurk (about.blsouqs.com) domains.
The plugin loader allocates RWX memory via VirtualAlloc, uses RtlQueueWorkItem to call LoadLibraryW for import resolution (evading EDR detection of LoadLibraryW calls from unbacked executable memory), and modifies PE headers to hinder static detection. Plugin module DLLs must export ins_ctl_db and oct_lk_col functions.
Zscaler ThreatLabz assesses with high confidence that BINDCLOAK is a variant of the OctLurk backdoor based on identical beacon message structures, the same encryption algorithm (zlib + double XOR), high XOR key similarity, shared infrastructure (SSL certificate reuse, Tucows registrar, Njalla name servers, ASN 14956), and operational overlaps (the actor pinged both BINDCLOAK and OctLurk C2 servers during post-compromise activity). Kaspersky GReAT separately documented OctLurk and a related backdoor (SilkLurk) targeting Central Asian governments and Syrian entities starting January 2025, attributed with medium confidence to a Chinese-speaking threat actor. The July 2026 campaign marks a notable geographic and sectoral expansion from Central Asian government targets to Middle Eastern energy sector entities.
MITRE ATT&CK techniques used in TL-2026-1858
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials
Defense Evasion
T1027 Obfuscated Files or Information; T1480 Execution Guardrails; T1497 Virtualization/Sandbox Evasion; T1620 Reflective Code Loading
Discovery
T1049 System Network Connections Discovery; T1057 Process Discovery; T1082 System Information Discovery
Persistence
Collection
T1056 Input Capture; T1113 Screen Capture; T1119 Automated Collection
Command and Control
T1095 Non-Application Layer Protocol; T1132 Data Encoding; T1573 Encrypted Channel
collection
Initial Access
stealth
Affected products and versions in BINDCLOAK: Previously Undocumented 64-bit Modular Windows
- Microsoft — Windows
Vulnerable versions: All versions supporting ImpersonateLoggedOnUser
Remediation for BINDCLOAK: Previously Undocumented 64-bit Modular Windows
Immediate actions
- Block C2 domains cert.hypersnet.com, about.blsouqs.com, ssl.blsouqs.com, contacts.ftabnews.com at perimeter
- Block IP 107.175.172.40 at firewall
- Deploy YARA signatures for BINDCLOAK (MD5 7a14a99d70d42d3f7bf72f843185fc07), TELESHIM, and MIXEDKEY hashes
- Scan for scheduled tasks named 'shimgen' and 'Feedback' on Windows endpoints
Workarounds
- Restrict execution of ISO files from email/downloads to administrative approval
- Enable Windows Defender Attack Surface Reduction rules for DLL side-loading
- Audit scheduled tasks for creation of unrecognized tasks with frequent intervals
Longer-term hardening
- Monitor for abnormal token usage (ImpersonateLoggedOnUser, DuplicateTokenEx calls from non-system processes)
- Monitor for RtlQueueWorkItem calling LoadLibraryW from unbacked memory regions
- Hunt for unscheduled TLS connections to Tucows/Njalla-registered domains on ASN 14956
- Monitor Telegram Bot API traffic from non-browser processes
- Implement ISO file execution telemetry and DLL side-loading detection
Timeline of BINDCLOAK: Previously Undocumented 64-bit Modular Windows
- Threat actor registers C2 infrastructure including about.blsouqs.com and ssl.blsouqs.com via Tucows registrar with Njalla name servers on ASN 14956
- OctLurk/SilkLurk operation begins targeting Central Asian governments (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan) and Syria, as documented by Kaspersky GReAT
- Diplomatic-themed ISO lures deployed targeting Middle Eastern energy sector entities, including petroleum and border-agreement themed filenames
- Current TELESHIM variant compiled (July 2026); two older variants previously compiled in 2025
- First observed post-compromise command execution in the Middle East campaign via TELESHIM backdoor, with reconnaissance and deployment of MIXEDKEY/BINDCLOAK
- Last day of observed post-compromise activity; actor verified connectivity to BINDCLOAK C2 (cert.hypersnet.com) and OctLurk C2 servers via ping commands
- Zscaler ThreatLabz publishes two-part analysis of the campaign; Kaspersky GReAT publishes OctLurk/SilkLurk report; Cybersecurity News publishes BINDCLOAK coverage
Sources cited for BINDCLOAK: Previously Undocumented 64-bit Modular Windows
- Zscaler ThreatLabz — Targeted Attack on Government Entities in the Middle East (Part 1)
- Zscaler ThreatLabz — Targeted Attack on Government Entities in the Middle East (Part 2)
- BINDCLOAK Steals Windows Tokens — Cybersecurity News
- OctLurk and SilkLurk: New Backdoors in Central Asia — Kaspersky Securelist
- Zscaler ThreatLabz — Win64.Backdoor.BINDCLOAK
- Zscaler ThreatLabz — Win32.Backdoor.TELESHIM
- Zscaler ThreatLabz — Win64.Loader.MIXEDKEY
- Kazakhstan STS — TrustFall/MystRodX Infrastructure Overlap
Detection coverage for TL-2026-1858
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1858 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.