BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

East Asia hackers target Middle East govts with new Telegram malware

East Asian hackers target Middle East with Telegram-based malware

  • A previously undocumented East Asian threat actor is targeting Middle East government agencies with three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.
  • The TELESHIM backdoor abuses the Telegram API for command-and-control communications, blending malicious traffic with legitimate internet activity.
  • The attack chain employs heavy code obfuscation and environmental keying, ensuring the final payload only executes on intended targets.
  • Post-compromise reconnaissance activity occurred primarily between July 7-9, 2026, during early morning UTC hours.

Cybersecurity researchers have flagged a sophisticated campaign by an East Asian threat actor targeting government entities in the Middle East. The intrusions deploy three previously unreported malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—according to Zscaler ThreatLabz.

- Advertisement -

The attack chain begins with an ISO file containing a legitimate executable used to sideload a rogue DLL. This 32-bit Windows backdoor, TELESHIM, then leverages the Telegram API for command-and-control communication to blend in with legitimate traffic, as detailed in a technical write-up by Zscaler.

Consequently, two of the retrieved payloads trigger a second DLL sideloading chain. This chain deploys a reflective loader named MIXEDKEY, which decrypts and executes additional malicious code.

Meanwhile, both TELESHIM and MIXEDKEY employ heavy code obfuscation techniques, including string encryption and control flow flattening, to hinder reverse engineering. TELESHIM also uses methods like hypervisor detection via CPUID and RAM speed checks to evade virtualized analysis environments.

Notably, the final payload is locked behind two layers of XOR encryption. The second layer uses environmental keying, deriving a decryption key from the infected machine’s volume serial number so the malware only detonates on intended targets.

- Advertisement -

The attack culminates with the deployment of BINDCLOAK, a 64-bit C2 implant that contacts an external server. Post-compromise activity included system, user, and network reconnaissance commands, with most operations occurring between July 7 and July 9, 2026.

Based on the threat actor’s IP address, system locale, and active operational hours, the campaign is assessed with moderate-to-high confidence as originating from East Asia. The activity reflects broader trends in EDR evasion and abuse of trusted platforms for malicious communications.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coinbase CEO: AI Makes Crypto More Important, Not Less

Coinbase CEO Brian Armstrong argues that crypto and AI are complementary, not competing, technologies.Armstrong...

Triple-A loses $11.8M in treasury wallet breach

Triple-A confirmed unauthorized access to its treasury wallets on Saturday, leading to the loss...

WEMIX halts services after $724K stablecoin contract breach

An attacker compromised a WEMIX$-linked contract, issuing unauthorized tokens and moving approximately $724,000 in...

CFTC issues second warning to prediction markets in 2024

The CFTC issued a second warning this year against overly generalized self-certification of event...

Strait of Hormuz Reopening Months Away, Experts Warn

Crypto traders anticipate a rally in Bitcoin and risk assets if oil prices decline...

Must Read

6 Best VPN Providers That Accept Monero

Privacy and anonymity are probably the most important things that we should all consider in today's internet era. Although there are a lot of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading