Threats Tagged 'backdoor'
View all threats tagged with 'backdoor'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'backdoor'
Click on any threat for detailed analysis and mitigation recommendations
Targeted Attack on Government Entities in the Middle East | Part 1 0 A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular Windows backdoor written in C++. BINDCLOAK is decrypted and reflectively loaded by MIXEDKEY loader as part of a complex attack chain. The backdoor employs advanced techniques including a complex message routing mechanism for C2 communications, EDR evasion to prevent detection of API calls from unbacked executable memory regions, and token manipulation for privilege escalation. Code similarities and shared infrastructure directly connect this activity to the OctLurk backdoor, representing an expansion from Central Asia operations to Middle East targeting with focus on energy sector. The threat actor demonstrates sophisticated development capabilities through custom encryption, modular plugin architecture, and careful operational security measures. Join the discussion | AlienVault OTX General | 08/03/2026, 21:38:36 UTC Added: 07/21/2026, 10:27:03 UTC |
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor 0 Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring. Join the discussion | AlienVault OTX General | 07/15/2026, 11:58:11 UTC Added: 07/15/2026, 21:47:49 UTC |
A hardware security AI assistant that checks chips for hidden backdoors 0 Researchers at the University of Florida developed VeriChat, an AI assistant designed to help hardware security engineers detect hidden backdoors in chip designs. VeriChat answers technical questions and runs verification tools on uploaded design files to identify suspicious elements. In a demonstration, VeriChat successfully detected a planted Trojan in an AES S-Box that leaked encryption keys upon a rare trigger sequence. The system uses a retrieval-based approach to ensure factual accuracy and refuses to speculate when evidence is insufficient. While promising, the tool's effectiveness against unknown or novel attacks remains unproven, and some evaluation methods rely on AI-based judgments. VeriChat aims to address supply chain risks by enabling engineers to interrogate and verify third-party hardware components more effectively. Join the discussion | Reddit Cybersecurity | 07/13/2026, 07:57:13 UTC Added: 07/13/2026, 08:02:24 UTC |
Showing 1 to 3 of 3 results