Introducing MERENA+ — our premium tier with your personalized safety dashboard, risk score, and all security tools. Sign up and cancel risk free in the first 14 days on the annual plan.Learn More
MERENA
Advisory Alert

BINDCLOAK Windows backdoor steals user and process tokens to run malware with higher privileges

Researchers found a hidden Windows program called BINDCLOAK that can help attackers gain deeper control over infected computers and run harmful actions under more trusted accounts. The activity has been linked to spying efforts aimed at government organizations in the Middle East.


Who is at risk

Government offices, public agencies, and organizations in the Middle East that use Windows computers are most at risk, especially if they manage sensitive information.

What to watch for

Watch for unusual computer behavior such as unexpected account activity, programs running that no one recognizes, or security tools reporting strange sign-ins or actions.

What to do

Immediately make sure Windows systems and security tools are fully updated, review admin and user account activity for anything unusual, and have IT teams investigate any suspicious devices.