Targeted Attack on Government Entities in the Middle East | Part 1
A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures.
AI Analysis
Technical Summary
This threat involves a multi-stage targeted attack campaign against Middle Eastern government entities by a threat actor with East Asian links. The campaign deployed novel malware: TELESHIM, which leverages Telegram API for stealthy C2 communications with heavy code obfuscation; MIXEDKEY, a reflective loader that derives decryption keys from the victim's volume serial number for environmental keying; and BINDCLOAK. The attacker demonstrated advanced tradecraft including DLL sideloading, anti-analysis techniques (hypervisor detection, RAM speed checks), and careful staging to evade detection. Post-compromise activities focused on reconnaissance and persistence from July 7-9, 2026, timed with East Asian working hours. The campaign targets government sectors and possibly energy sectors, using modular backdoors and sophisticated evasion techniques.
Potential Impact
The campaign enables persistent unauthorized access to targeted government entities, allowing the threat actor to conduct reconnaissance and maintain long-term presence. The use of novel malware and advanced evasion techniques complicates detection and response efforts. The abuse of legitimate services like Telegram for C2 communication increases stealthiness. The impact includes potential data exfiltration, espionage, and disruption of critical government operations in the Middle East.
Mitigation Recommendations
No official patches or fixes are available as this is a targeted attack campaign using custom malware. Defenders should monitor for indicators of compromise associated with TELESHIM, MIXEDKEY, and BINDCLOAK, and implement detection for DLL sideloading and unusual use of Telegram API for network communications. Employ advanced endpoint detection and response (EDR) solutions capable of detecting code obfuscation and anti-analysis behaviors. Network segmentation and restricting unauthorized use of messaging APIs may reduce exposure. Review security telemetry for signs of reconnaissance and persistence activities during the noted timeframe. Since this is a targeted campaign, tailored threat hunting and incident response are recommended.
Indicators of Compromise
- hash: 087499849115eb28c4364581d2b28d09
- hash: 28b47bdf16d7af6f8ec21218eac9145a
- hash: 3f60d53a2b5737d77e058d9e33cbe9eb
- hash: 68926e6c958562deaae35de3d9f59de3
- hash: 78a4f8574830bf7fbaf63d7da09be2b8
- hash: 7a14a99d70d42d3f7bf72f843185fc07
- hash: 7cbc51ada1a4aec88660ec32c408114b
- hash: 97124a93766be732e8fef5a56a5346a2
- hash: b776eb638fbb535708fb92b12fcc1731
- hash: c99f29ac08454855b3d538960bb2f34f
- hash: 1099bf51e53bd5fb32401edb4e0be841d8486b19
- hash: 2377c47cfde148c2140faa7105628174f9c4d56d
- hash: 577b1cc894636f4ac5ad670b0079b9b7ade137c3
- hash: 86ee99f293a30720bcc898a4a8e391f93fb9be95
- hash: c1f16e31ae71372ee45fa6fd6927c7b887a4e3f2
- hash: ccb2002fe8f5cc1f511d52309625b52d1c507421
- hash: ee287d6a09295502ab2407aec336f9f0d8477d68
- hash: f46c01a5be2e08e36d4ec3302a8650a6ed25ec14
- hash: fee6806c96f87bf1e240a2eb6fd7e045101d58d3
- hash: 0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9
- hash: 32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66
- hash: 3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d
- hash: 3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f
- hash: 5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d
- hash: 789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd
- hash: c84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f
- hash: cac1f37beaa814461f7709a073aeec468c74e5d70f7d693a9e367ece4a3a78be
- hash: db11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b
- domain: cert.hypersnet.com
- domain: ftabnews.com
- domain: contacts.ftabnews.com
- domain: ssl.blsouqs.com
- domain: about.blsouqs.com
- hash: 59fe1ef7707fe497d89f34505222862f
Targeted Attack on Government Entities in the Middle East | Part 1
Description
A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a multi-stage targeted attack campaign against Middle Eastern government entities by a threat actor with East Asian links. The campaign deployed novel malware: TELESHIM, which leverages Telegram API for stealthy C2 communications with heavy code obfuscation; MIXEDKEY, a reflective loader that derives decryption keys from the victim's volume serial number for environmental keying; and BINDCLOAK. The attacker demonstrated advanced tradecraft including DLL sideloading, anti-analysis techniques (hypervisor detection, RAM speed checks), and careful staging to evade detection. Post-compromise activities focused on reconnaissance and persistence from July 7-9, 2026, timed with East Asian working hours. The campaign targets government sectors and possibly energy sectors, using modular backdoors and sophisticated evasion techniques.
Potential Impact
The campaign enables persistent unauthorized access to targeted government entities, allowing the threat actor to conduct reconnaissance and maintain long-term presence. The use of novel malware and advanced evasion techniques complicates detection and response efforts. The abuse of legitimate services like Telegram for C2 communication increases stealthiness. The impact includes potential data exfiltration, espionage, and disruption of critical government operations in the Middle East.
Defensive Guidance
No official patches or fixes are available as this is a targeted attack campaign using custom malware. Defenders should monitor for indicators of compromise associated with TELESHIM, MIXEDKEY, and BINDCLOAK, and implement detection for DLL sideloading and unusual use of Telegram API for network communications. Employ advanced endpoint detection and response (EDR) solutions capable of detecting code obfuscation and anti-analysis behaviors. Network segmentation and restricting unauthorized use of messaging APIs may reduce exposure. Review security telemetry for signs of reconnaissance and persistence activities during the noted timeframe. Since this is a targeted campaign, tailored threat hunting and incident response are recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1"]
- Adversary
- null
- Pulse Id
- 6a5e772bc58d968a512e89c4
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash087499849115eb28c4364581d2b28d09 | — | |
hash28b47bdf16d7af6f8ec21218eac9145a | — | |
hash3f60d53a2b5737d77e058d9e33cbe9eb | — | |
hash68926e6c958562deaae35de3d9f59de3 | — | |
hash78a4f8574830bf7fbaf63d7da09be2b8 | — | |
hash7a14a99d70d42d3f7bf72f843185fc07 | — | |
hash7cbc51ada1a4aec88660ec32c408114b | — | |
hash97124a93766be732e8fef5a56a5346a2 | — | |
hashb776eb638fbb535708fb92b12fcc1731 | — | |
hashc99f29ac08454855b3d538960bb2f34f | — | |
hash1099bf51e53bd5fb32401edb4e0be841d8486b19 | — | |
hash2377c47cfde148c2140faa7105628174f9c4d56d | — | |
hash577b1cc894636f4ac5ad670b0079b9b7ade137c3 | — | |
hash86ee99f293a30720bcc898a4a8e391f93fb9be95 | — | |
hashc1f16e31ae71372ee45fa6fd6927c7b887a4e3f2 | — | |
hashccb2002fe8f5cc1f511d52309625b52d1c507421 | — | |
hashee287d6a09295502ab2407aec336f9f0d8477d68 | — | |
hashf46c01a5be2e08e36d4ec3302a8650a6ed25ec14 | — | |
hashfee6806c96f87bf1e240a2eb6fd7e045101d58d3 | — | |
hash0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9 | — | |
hash32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66 | — | |
hash3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d | — | |
hash3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f | — | |
hash5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d | — | |
hash789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd | — | |
hashc84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f | — | |
hashcac1f37beaa814461f7709a073aeec468c74e5d70f7d693a9e367ece4a3a78be | — | |
hashdb11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b | — | |
hash59fe1ef7707fe497d89f34505222862f | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaincert.hypersnet.com | — | |
domainftabnews.com | — | |
domaincontacts.ftabnews.com | — | |
domainssl.blsouqs.com | — | |
domainabout.blsouqs.com | — |
Threat ID: 6a5f49772a4a8d5989f62c1d
Added to database: 07/21/2026, 10:27:03 UTC
Last enriched: 08/04/2026, 12:37:31 UTC
Last updated: 09/03/2026, 06:47:59 UTC
Views: 656
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.