TELESHIM Malware Campaign: Telegram C2 Targets Governments
ID: ccff4eec-f7d0-5501-aee9-f918f12bcb74
STIX ID: report--ccff4eec-f7d0-5501-aee9-f918f12bcb74
Feed Name: CyberNexora News
## Executive Summary: The TELESHIM Malware Campaign is a newly discovered, multi-stage espionage operation targeting government entities in the Middle East that leverages Telegram's API for stealthy command-and-control, employs DLL sideloading and environmental keying to limit execution to intended hosts, and deploys additional modules (MIXEDKEY, BINDCLOAK) for persistence, reconnaissance, and data exfiltration; Zscaler ThreatLabz provides technical analysis, IoCs, and TTPs and links the activity with moderate-to-high confidence to an East Asia–associated actor, though no formal APT attribution has been made.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
