Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Targeted Attack on Government Entities in the Middle East | Part 1

0
Medium
Published: 08/03/2026 (08/03/2026, 21:38:36 UTC)
Source: AlienVault OTX General

Description

A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 12:37:31 UTC

Technical Analysis

This threat involves a multi-stage targeted attack campaign against Middle Eastern government entities by a threat actor with East Asian links. The campaign deployed novel malware: TELESHIM, which leverages Telegram API for stealthy C2 communications with heavy code obfuscation; MIXEDKEY, a reflective loader that derives decryption keys from the victim's volume serial number for environmental keying; and BINDCLOAK. The attacker demonstrated advanced tradecraft including DLL sideloading, anti-analysis techniques (hypervisor detection, RAM speed checks), and careful staging to evade detection. Post-compromise activities focused on reconnaissance and persistence from July 7-9, 2026, timed with East Asian working hours. The campaign targets government sectors and possibly energy sectors, using modular backdoors and sophisticated evasion techniques.

Potential Impact

The campaign enables persistent unauthorized access to targeted government entities, allowing the threat actor to conduct reconnaissance and maintain long-term presence. The use of novel malware and advanced evasion techniques complicates detection and response efforts. The abuse of legitimate services like Telegram for C2 communication increases stealthiness. The impact includes potential data exfiltration, espionage, and disruption of critical government operations in the Middle East.

Defensive Guidance

No official patches or fixes are available as this is a targeted attack campaign using custom malware. Defenders should monitor for indicators of compromise associated with TELESHIM, MIXEDKEY, and BINDCLOAK, and implement detection for DLL sideloading and unusual use of Telegram API for network communications. Employ advanced endpoint detection and response (EDR) solutions capable of detecting code obfuscation and anti-analysis behaviors. Network segmentation and restricting unauthorized use of messaging APIs may reduce exposure. Review security telemetry for signs of reconnaissance and persistence activities during the noted timeframe. Since this is a targeted campaign, tailored threat hunting and incident response are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1"]
Adversary
null
Pulse Id
6a5e772bc58d968a512e89c4
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash087499849115eb28c4364581d2b28d09
hash28b47bdf16d7af6f8ec21218eac9145a
hash3f60d53a2b5737d77e058d9e33cbe9eb
hash68926e6c958562deaae35de3d9f59de3
hash78a4f8574830bf7fbaf63d7da09be2b8
hash7a14a99d70d42d3f7bf72f843185fc07
hash7cbc51ada1a4aec88660ec32c408114b
hash97124a93766be732e8fef5a56a5346a2
hashb776eb638fbb535708fb92b12fcc1731
hashc99f29ac08454855b3d538960bb2f34f
hash1099bf51e53bd5fb32401edb4e0be841d8486b19
hash2377c47cfde148c2140faa7105628174f9c4d56d
hash577b1cc894636f4ac5ad670b0079b9b7ade137c3
hash86ee99f293a30720bcc898a4a8e391f93fb9be95
hashc1f16e31ae71372ee45fa6fd6927c7b887a4e3f2
hashccb2002fe8f5cc1f511d52309625b52d1c507421
hashee287d6a09295502ab2407aec336f9f0d8477d68
hashf46c01a5be2e08e36d4ec3302a8650a6ed25ec14
hashfee6806c96f87bf1e240a2eb6fd7e045101d58d3
hash0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9
hash32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66
hash3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d
hash3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f
hash5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d
hash789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd
hashc84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f
hashcac1f37beaa814461f7709a073aeec468c74e5d70f7d693a9e367ece4a3a78be
hashdb11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b
hash59fe1ef7707fe497d89f34505222862f

Domain

ValueDescriptionCopy
domaincert.hypersnet.com
domainftabnews.com
domaincontacts.ftabnews.com
domainssl.blsouqs.com
domainabout.blsouqs.com

Threat ID: 6a5f49772a4a8d5989f62c1d

Added to database: 07/21/2026, 10:27:03 UTC

Last enriched: 08/04/2026, 12:37:31 UTC

Last updated: 09/03/2026, 06:47:59 UTC

Views: 656

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses