BINDCLOAK Windows backdoor steals user and process tokens to run malware with higher privileges
Researchers found a hidden Windows program called BINDCLOAK that can help attackers gain deeper control over infected computers and run harmful actions under more trusted accounts. The activity has been linked to spying efforts aimed at government organizations in the Middle East.
Who is at risk
Government offices, public agencies, and organizations in the Middle East that use Windows computers are most at risk, especially if they manage sensitive information.
What to watch for
Watch for unusual computer behavior such as unexpected account activity, programs running that no one recognizes, or security tools reporting strange sign-ins or actions.
What to do
Immediately make sure Windows systems and security tools are fully updated, review admin and user account activity for anything unusual, and have IT teams investigate any suspicious devices.
