logo

Targeted Attack on Government Entities in the Middle East | Part 1

ID: 1292c5df-cb8f-59fd-bb9a-8bfe0cc0dd29

STIX ID: report--1292c5df-cb8f-59fd-bb9a-8bfe0cc0dd29

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Sudeep Singh (Sr. Manager, APT Research)

...
...

Zscaler ThreatLabz observed a targeted, multi-stage intrusion (July 2026) against government entities in the Middle East that deployed undocumented malware implants TELESHIM (32-bit DLL backdoor using Telegram-based C2), MIXEDKEY (64-bit reflective loader with environment-keyed decryption), and BINDCLOAK (final 64-bit C2 implant). The report details initial delivery via a signed ASUSTek executable sideloading AsTaskSched.dll, heavy code obfuscation (CFF, MBA, opaque predicates), anti-analysis checks, persistence via scheduled tasks, environmental keying tied to the drive volume serial, captured post-compromise operator activity (reconnaissance, staging, deployment), and multiple IOCs (file hashes, filenames, C2 domain).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.