BACKBEND
- Malware type
- downloader
- Profile updated
- 2026-07-07 12:36:39
Targeted industries: defense-and-aerospace government-and-public-sector
Context
FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed. When executed, BACKBEND checks for the presence of the mutexes MicrosoftZj or MicrosoftZjBak (both associated with BACKSPACE variants). If either of the mutexes exist, the malware exits.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Backbend_Auto (yara-rule)
Reports & references
- Mandiant — Rpt Apt30 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Backbend (report)