BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

East Asia hackers target Middle East govts with new Telegram malware

East Asian hackers target Middle East with Telegram-based malware

  • A previously undocumented East Asian threat actor is targeting Middle East government agencies with three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.
  • The TELESHIM backdoor abuses the Telegram API for command-and-control communications, blending malicious traffic with legitimate internet activity.
  • The attack chain employs heavy code obfuscation and environmental keying, ensuring the final payload only executes on intended targets.
  • Post-compromise reconnaissance activity occurred primarily between July 7-9, 2026, during early morning UTC hours.

Cybersecurity researchers have flagged a sophisticated campaign by an East Asian threat actor targeting government entities in the Middle East. The intrusions deploy three previously unreported malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—according to Zscaler ThreatLabz.

- Advertisement -

The attack chain begins with an ISO file containing a legitimate executable used to sideload a rogue DLL. This 32-bit Windows backdoor, TELESHIM, then leverages the Telegram API for command-and-control communication to blend in with legitimate traffic, as detailed in a technical write-up by Zscaler.

Consequently, two of the retrieved payloads trigger a second DLL sideloading chain. This chain deploys a reflective loader named MIXEDKEY, which decrypts and executes additional malicious code.

Meanwhile, both TELESHIM and MIXEDKEY employ heavy code obfuscation techniques, including string encryption and control flow flattening, to hinder reverse engineering. TELESHIM also uses methods like hypervisor detection via CPUID and RAM speed checks to evade virtualized analysis environments.

Notably, the final payload is locked behind two layers of XOR encryption. The second layer uses environmental keying, deriving a decryption key from the infected machine’s volume serial number so the malware only detonates on intended targets.

- Advertisement -

The attack culminates with the deployment of BINDCLOAK, a 64-bit C2 implant that contacts an external server. Post-compromise activity included system, user, and network reconnaissance commands, with most operations occurring between July 7 and July 9, 2026.

Based on the threat actor’s IP address, system locale, and active operational hours, the campaign is assessed with moderate-to-high confidence as originating from East Asia. The activity reflects broader trends in EDR evasion and abuse of trusted platforms for malicious communications.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Adobe Patches Critical Magento Flaw Under Active Attack

Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day in Commerce and Magento Open Source exploited...

Polish court detains fifth suspect in Zondacrypto fraud case

A Polish court approved pretrial detention for Roman Ż., charged with computer fraud and...

Bitcoin-Gold Correlation Hits 6-Year High as Hedge Demand Rises

Bitcoin's correlation with Gold hits a six-year high, signaling its use as a hedge...

Cronos confirms $9.2M slipped away before Tectonic exploit rollback

Cronos confirmed $9.19 million left its blockchain before a network rollback reversed a crypto...

Presearch Shut Down and Left Me With 60 Cents. Their Own Filings Show Why.

I bought €100 of PRE about two and a half years ago. I was...

Must Read

17 Best Cryptocurrency Wallets

If you are looking for a list with the best cryptocurrency wallets, then you've landed on the right page. Cryptocurrency, as we all know,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading