Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:29:06 UTC Home > List all groups > List all tools > List all groups using tool BackBend Tool: BackBend Names BackBend Category Malware Type Downloader Description FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed. When executed, BACKBEND checks for the presence of the mutexes MicrosoftZj or MicrosoftZjBak (both associated with Backspace variants). If either of the mutexes exist, the malware exits. Information Malpedia AlienVault OTX Last change to this tool card: 23 April 2020 Download this tool card in JSON format All groups using tool BackBend Changed Name Country Observed APT groups   APT 30, Override Panda 2005     Naikon, Lotus Panda 2010-Apr 2022   2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=37dfba7c-7342-4b75-b3a1-3222f329562d https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=37dfba7c-7342-4b75-b3a1-3222f329562d Page 1 of 1