East Asian Threat Actor Targets Middle Eastern Governments with New Malware
ID: afcbc275-8fa7-5947-9684-57cf340200ca
STIX ID: report--afcbc275-8fa7-5947-9684-57cf340200ca
Feed Name: ThreatCluster
In July 2026 Zscaler ThreatLabz identified a targeted campaign by an East Asian threat actor against Middle Eastern government entities that used a multi-stage infection chain delivered via an ISO which sideloaded a malicious DLL through a legitimate ASUSTek executable; previously undocumented implants TELESHIM, MIXEDKEY, and BINDCLOAK were deployed, with TELESHIM leveraging the Telegram API for C2 and employing advanced obfuscation and encrypted strings to evade detection, and further analysis of BINDCLOAK is expected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
