Cyber Security News

BINDCLOAK Steals Windows User and Process Tokens to Run Malware With Higher Privileges

A newly uncovered Windows backdoor is giving an East Asia-linked espionage operation a quiet way to deepen control inside targeted networks.

Named BINDCLOAK, the modular implant is deployed after initial access and can run malware using more powerful user or process accounts.

The campaign targeted government entities in the Middle East, with a particular focus on the energy sector.

Attackers used a multi-stage chain that began with an ISO file and legitimate-looking Windows components before delivering TELESHIM, MIXEDKEY, and finally BINDCLOAK.

A related report on Telegram bot backdoor controllers explains how the earlier TELESHIM component helped operators manage compromised systems.

Analysts at Zscaler identified BINDCLOAK as a previously undocumented 64-bit Windows backdoor written in C. 

Zscaler said in a report shared with Cyber Security News (CSN) that the malware was decrypted and reflectively loaded by MIXEDKEY during post-compromise activity.

The discovery shows how attackers can turn stolen Windows access tokens into a practical privilege escalation tool.

Instead of relying only on a software flaw, BINDCLOAK collects available tokens and uses them to launch its modules with the rights of a more privileged account.

BINDCLOAK Steals Windows User and Process Tokens

BINDCLOAK has commands to collect user tokens, inspect running processes, and identify tokens that can be copied or assigned to new processes.

It can attempt to log in with supplied credentials, retain a successful user token, and later use that token to start a selected module.

The backdoor also examines active processes for their IDs, account details, and token permissions.

That allows the operator to select a process token that may offer stronger access, then duplicate it and start a BINDCLOAK module in that security context.

This approach is especially dangerous because access-token abuse can blend into normal Windows behavior.

Recent Windows privilege escalation research has also shown how gaining SYSTEM-level access can give an attacker broad control of an affected machine.

Once a module receives a higher-privileged token, BINDCLOAK calls the Windows ImpersonateLoggedOnUser function so its activity runs under that account.

The malware can also stop, remove, and replace modules, helping operators adjust their tools without reinstalling the full backdoor.

Modular Backdoor Evades Detection

BINDCLOAK communicates with its command server through TLS over TCP, using a custom message-routing system.

Its messages are compressed, encrypted twice with rolling XOR keys, padded with random data, and then delivered to the relevant internal module.

The malware collects a wide range of host information for its first beacon, including the operating-system version, computer name, username, hostname, local IP address, and local time.

This gives attackers a quick view of each infected system before they decide which commands or plugins to deploy.

Its plugin loader creates memory with read, write, and execute permissions, then loads additional DLL modules directly into memory.

To avoid alerts, it uses RtlQueueWorkItem to invoke LoadLibraryW, a technique intended to make suspicious loading behavior less obvious to endpoint security tools.

Similar concerns apply when attackers abuse legitimate processes for malicious DLL payload injection, which can hide code behind trusted Windows activity.

Researchers assessed with high confidence that BINDCLOAK is a variant of the OctLurk backdoor, citing code similarities and overlapping command-and-control infrastructure.

The same operator appears to have expanded from Central Asia into Middle Eastern targets, underscoring the need to review abnormal token use, unexpected DLL loading, and suspicious outbound TLS connections.

Security teams should investigate unknown ISO files, unusual scheduled tasks, DLLs placed beside trusted executables, and processes launching under unexpected user contexts.

Monitoring anomalous process-token access and reviewing suspicious web-server activity can also support broader cross-platform intrusion investigations.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
MD5 hash7a14a99d70d42d3f7bf72f843185fc07BINDCLOAK DLL sample
SHA-1 hash577b1cc894636f4ac5ad670b0079b9b7ade137c3BINDCLOAK sample
SHA-256 hash3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669dBINDCLOAK sample
C2 domaincert.hypersnet.comBINDCLOAK command-and-control domain
C2 domainabout.blsouqs.comOctLurk command-and-control domain sharing an SSL certificate
C2 domainssl.blsouqs.comOctLurk infrastructure contacted during post-compromise activity
Domaincontacts.ftabnews.comDomain contacted during post-compromise activity
Domainftabnews.comInfrastructure assessed as potentially used for command and control
IP address107.175.172.40Common Name in SSL certificate associated with cert.hypersnet.com
SSL certificate serial59fe1ef7707fe497d89f34505222862fCertificate reused across BINDCLOAK and OctLurk infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago