BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

East Asia hackers target Middle East govts with new Telegram malware

East Asian hackers target Middle East with Telegram-based malware

  • A previously undocumented East Asian threat actor is targeting Middle East government agencies with three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.
  • The TELESHIM backdoor abuses the Telegram API for command-and-control communications, blending malicious traffic with legitimate internet activity.
  • The attack chain employs heavy code obfuscation and environmental keying, ensuring the final payload only executes on intended targets.
  • Post-compromise reconnaissance activity occurred primarily between July 7-9, 2026, during early morning UTC hours.

Cybersecurity researchers have flagged a sophisticated campaign by an East Asian threat actor targeting government entities in the Middle East. The intrusions deploy three previously unreported malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—according to Zscaler ThreatLabz.

- Advertisement -

The attack chain begins with an ISO file containing a legitimate executable used to sideload a rogue DLL. This 32-bit Windows backdoor, TELESHIM, then leverages the Telegram API for command-and-control communication to blend in with legitimate traffic, as detailed in a technical write-up by Zscaler.

Consequently, two of the retrieved payloads trigger a second DLL sideloading chain. This chain deploys a reflective loader named MIXEDKEY, which decrypts and executes additional malicious code.

Meanwhile, both TELESHIM and MIXEDKEY employ heavy code obfuscation techniques, including string encryption and control flow flattening, to hinder reverse engineering. TELESHIM also uses methods like hypervisor detection via CPUID and RAM speed checks to evade virtualized analysis environments.

Notably, the final payload is locked behind two layers of XOR encryption. The second layer uses environmental keying, deriving a decryption key from the infected machine’s volume serial number so the malware only detonates on intended targets.

- Advertisement -

The attack culminates with the deployment of BINDCLOAK, a 64-bit C2 implant that contacts an external server. Post-compromise activity included system, user, and network reconnaissance commands, with most operations occurring between July 7 and July 9, 2026.

Based on the threat actor’s IP address, system locale, and active operational hours, the campaign is assessed with moderate-to-high confidence as originating from East Asia. The activity reflects broader trends in EDR evasion and abuse of trusted platforms for malicious communications.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Jane Street Boosts Bitcoin, XRP ETF Holdings in Q2 Filing

Jane Street more than doubled its Bitcoin ETF holdings in Q2 to roughly $1.01...

Upbit, Bithumb revenues plummet; Polymarket banned

Upbit parent company Dunamu reported a 49% drop in first-half operating revenue to $289...

MoonPay integrates Cash App Pay for crypto purchases

MoonPay has integrated Cash App Pay as a new payment option for US users...

StubMaker: 16 typosquat RubyGems packages steal data

Cybersecurity researchers have discovered a new typosquatting campaign, tracked as StubMaker, targeting RubyGems users...

Gold Slips 0.4% to $4,397 on Rising Yields, Oil

Gold prices fell 0.4% today, August 18, 2026, amid rising US Treasury yields and...

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading