TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
ID: 090466e9-2a80-5d61-a3d1-7a7dc97acbe6
STIX ID: report--090466e9-2a80-5d61-a3d1-7a7dc97acbe6
Feed Name: The Hacker News
Zscaler ThreatLabz observed a multi-stage targeted campaign (July 7–9, 2026) against government entities in the Middle East using three previously unreported malware families — TELESHIM (32-bit backdoor using Telegram for C2), MIXEDKEY (reflective loader/decrypter used in DLL sideloading), and BINDCLOAK (64-bit C++ C2 implant contacting cert.hypersnet.com). The attack chain begins with an ISO that sideloads malicious DLLs and leverages heavy code obfuscation, virtualization checks, environmental keying (volume serial-based XOR decryption) and scheduled-task based payload execution to evade analysis and ensure detonation only on intended targets; observed activity and metadata yielded a moderate-to-high confidence assessment of East Asia origin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
