A newly discovered Windows backdoor named BINDCLOAK is providing a stealthy method for an East Asia-linked espionage operation to enhance its presence within targeted networks. The malware collects a variety of host information for its first beacon, including operating-system version, computer name, username, hostname, local IP address, and local time. To avoid detection, it uses RtlQueueWorkItem to invoke LoadLibraryW, a technique intended to make suspicious loading behavior less apparent to endpoint security tools.

The same operator has expanded from Central Asia into Middle Eastern targets, highlighting the importance of reviewing abnormal token usage, unexpected DLL loading, and suspicious outbound TLS connections. Security teams should investigate unknown ISO files, unusual scheduled tasks, DLLs placed beside trusted executables, and processes running under unexpected user contexts.

The following are indicators of compromise (IoCs): - MD5 hash: BINDCLOAK sample - SHA-1 hash: BINDCLOAK sample - SHA-256 hash: BINDCLOAK sample - C2 domain cert.hypersnet.com: BINDCLOK command-and-control domain - C2 domain about.blsouqs.com: OctLurk command-and-control domain sharing an SSL certificate - C2 domain ssl.blsouqs.com: OctLurk infrastructure contacted during post-compromise activity - Domain contacts.ftabnews.com: Domain contacted during post-compromise activity - Domain ftabnews.com: Infrastructure assessed as potentially used for command and control - IP address 107.175.172.40: Common Name in SSL certificate associated with cert.hypersnet.com - SSL certificate serial 59fe1ef7707fe497d89f34505222862f: Certificate reused across BINDCLOAK and OctLurk infrastructure