- A previously undocumented East Asian threat actor is targeting Middle East government agencies with three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.
- The TELESHIM backdoor abuses the Telegram API for command-and-control communications, blending malicious traffic with legitimate internet activity.
- The attack chain employs heavy code obfuscation and environmental keying, ensuring the final payload only executes on intended targets.
- Post-compromise reconnaissance activity occurred primarily between July 7-9, 2026, during early morning UTC hours.
Cybersecurity researchers have flagged a sophisticated campaign by an East Asian threat actor targeting government entities in the Middle East. The intrusions deploy three previously unreported malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—according to Zscaler ThreatLabz.
The attack chain begins with an ISO file containing a legitimate executable used to sideload a rogue DLL. This 32-bit Windows backdoor, TELESHIM, then leverages the Telegram API for command-and-control communication to blend in with legitimate traffic, as detailed in a technical write-up by Zscaler.
Consequently, two of the retrieved payloads trigger a second DLL sideloading chain. This chain deploys a reflective loader named MIXEDKEY, which decrypts and executes additional malicious code.
Meanwhile, both TELESHIM and MIXEDKEY employ heavy code obfuscation techniques, including string encryption and control flow flattening, to hinder reverse engineering. TELESHIM also uses methods like hypervisor detection via CPUID and RAM speed checks to evade virtualized analysis environments.
Notably, the final payload is locked behind two layers of XOR encryption. The second layer uses environmental keying, deriving a decryption key from the infected machine’s volume serial number so the malware only detonates on intended targets.
The attack culminates with the deployment of BINDCLOAK, a 64-bit C2 implant that contacts an external server. Post-compromise activity included system, user, and network reconnaissance commands, with most operations occurring between July 7 and July 9, 2026.
Based on the threat actor’s IP address, system locale, and active operational hours, the campaign is assessed with moderate-to-high confidence as originating from East Asia. The activity reflects broader trends in EDR evasion and abuse of trusted platforms for malicious communications.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
