logo

TELESHIM Malware Campaign: Telegram C2 Targets Governments

ID: ccff4eec-f7d0-5501-aee9-f918f12bcb74

STIX ID: report--ccff4eec-f7d0-5501-aee9-f918f12bcb74

Feed Name: CyberNexora News

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Debolina Barik

...
...

## Executive Summary: The TELESHIM Malware Campaign is a newly discovered, multi-stage espionage operation targeting government entities in the Middle East that leverages Telegram's API for stealthy command-and-control, employs DLL sideloading and environmental keying to limit execution to intended hosts, and deploys additional modules (MIXEDKEY, BINDCLOAK) for persistence, reconnaissance, and data exfiltration; Zscaler ThreatLabz provides technical analysis, IoCs, and TTPs and links the activity with moderate-to-high confidence to an East Asia–associated actor, though no formal APT attribution has been made.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.