Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments
ID: a622b63a-58be-5134-a8a7-8b809a9b783f
STIX ID: report--a622b63a-58be-5134-a8a7-8b809a9b783f
Feed Name: GBHackers
A technical analysis describes an active, sophisticated multi-stage intrusion (July 7–9, 2026) attributed to an East Asia–linked actor targeting government entities in the Middle East. Attackers used weaponized ISO files and DLL sideloading of legitimate ASUS-signed binaries to load a 32-bit TELESHIM backdoor (obfuscated with CFF, MBA, opaque predicates and anti-analysis checks), followed by a MIXEDKEY loader and final BINDCLOAK implant. TELESHIM abuses the Telegram Bot API for encrypted C2 polling, validates commands per-MAC address, and exfiltrates data in encrypted chunks; IOCs (file hashes, filenames, staging directories and defanged domains) are provided, and the report recommends behavioral detection and API/traffic monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
