logo

Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments

ID: a622b63a-58be-5134-a8a7-8b809a9b783f

STIX ID: report--a622b63a-58be-5134-a8a7-8b809a9b783f

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A technical analysis describes an active, sophisticated multi-stage intrusion (July 7–9, 2026) attributed to an East Asia–linked actor targeting government entities in the Middle East. Attackers used weaponized ISO files and DLL sideloading of legitimate ASUS-signed binaries to load a 32-bit TELESHIM backdoor (obfuscated with CFF, MBA, opaque predicates and anti-analysis checks), followed by a MIXEDKEY loader and final BINDCLOAK implant. TELESHIM abuses the Telegram Bot API for encrypted C2 polling, validates commands per-MAC address, and exfiltrates data in encrypted chunks; IOCs (file hashes, filenames, staging directories and defanged domains) are provided, and the report recommends behavioral detection and API/traffic monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.