BACKBEND

Malware type
downloader
Profile updated
2026-07-07 12:36:39

Targeted industries: defense-and-aerospace government-and-public-sector

Context

FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed. When executed, BACKBEND checks for the presence of the mutexes MicrosoftZj or MicrosoftZjBak (both associated with BACKSPACE variants). If either of the mutexes exist, the malware exits.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Backbend_Auto (yara-rule)

Reports & references

  • Mandiant — Rpt Apt30 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Backbend (report)

External references