BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

East Asia hackers target Middle East govts with new Telegram malware

East Asian hackers target Middle East with Telegram-based malware

  • A previously undocumented East Asian threat actor is targeting Middle East government agencies with three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.
  • The TELESHIM backdoor abuses the Telegram API for command-and-control communications, blending malicious traffic with legitimate internet activity.
  • The attack chain employs heavy code obfuscation and environmental keying, ensuring the final payload only executes on intended targets.
  • Post-compromise reconnaissance activity occurred primarily between July 7-9, 2026, during early morning UTC hours.

Cybersecurity researchers have flagged a sophisticated campaign by an East Asian threat actor targeting government entities in the Middle East. The intrusions deploy three previously unreported malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—according to Zscaler ThreatLabz.

- Advertisement -

The attack chain begins with an ISO file containing a legitimate executable used to sideload a rogue DLL. This 32-bit Windows backdoor, TELESHIM, then leverages the Telegram API for command-and-control communication to blend in with legitimate traffic, as detailed in a technical write-up by Zscaler.

Consequently, two of the retrieved payloads trigger a second DLL sideloading chain. This chain deploys a reflective loader named MIXEDKEY, which decrypts and executes additional malicious code.

Meanwhile, both TELESHIM and MIXEDKEY employ heavy code obfuscation techniques, including string encryption and control flow flattening, to hinder reverse engineering. TELESHIM also uses methods like hypervisor detection via CPUID and RAM speed checks to evade virtualized analysis environments.

Notably, the final payload is locked behind two layers of XOR encryption. The second layer uses environmental keying, deriving a decryption key from the infected machine’s volume serial number so the malware only detonates on intended targets.

- Advertisement -

The attack culminates with the deployment of BINDCLOAK, a 64-bit C2 implant that contacts an external server. Post-compromise activity included system, user, and network reconnaissance commands, with most operations occurring between July 7 and July 9, 2026.

Based on the threat actor’s IP address, system locale, and active operational hours, the campaign is assessed with moderate-to-high confidence as originating from East Asia. The activity reflects broader trends in EDR evasion and abuse of trusted platforms for malicious communications.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tesla signs $30B unused credit lines for the AI and robotics

Tesla signed $30 billion in unused senior unsecured bank facilities, including a $20 billion...

New Spectre-v2 CPU Variant ‘BTR’ Hits JIT Engines

Academics disclosed a new Spectre-v2 CPU vulnerability variant, Branch Target Reuse (BTR), affecting JIT...

Cboe, S&P Extend Deal, Eye Tokenized Options

Cboe Global Markets and S&P Dow Jones Indices extended their exclusive licensing agreement through...

OpenAI launches Dots assistant, seeks $30B funding

OpenAI launched "Dots," a persistent virtual assistant operating computers and debugging software autonomously.The company...

Healey jabs Farage with ‘BTC account’ Truss comparison

UK Chancellor John Healey mocked Nigel Farage's fiscal plans by comparing them to a...

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading