By Interestana AI Editorial — AI-drafted, human-overseen. How we report
TELESHIM Abuses Telegram for C2 in Middle East Government Attacks

Cybersecurity researchers have identified a new wave of malicious cyber activity orchestrated by a threat actor linked to East Asia, specifically targeting government entities within the Middle East. This campaign, detected earlier this month by Zscaler ThreatLabz, has led to the deployment of several previously undocumented malware families. Among these newly discovered tools are TELESHIM, MIXEDKEY, and BINDCLOAK, each playing a role in the intrusion and command-and-control infrastructure.
The TELESHIM malware is particularly noteworthy for its innovative use of the widely adopted Telegram messaging application as a command-and-control (C2) channel. This method allows the threat actor to communicate with compromised systems discreetly, leveraging Telegram's encrypted messaging and broad user base to evade detection. By disguising malicious commands and data exfiltration as regular Telegram traffic, the attackers can maintain persistence and operational control over targeted networks without raising immediate suspicion from traditional security monitoring tools. The use of a popular consumer platform for such sophisticated cyber espionage highlights a growing trend among advanced persistent threat (APT) groups to exploit legitimate services for malicious purposes.
In addition to TELESHIM, the threat actor has deployed MIXEDKEY and BINDCLOAK. MIXEDKEY appears to function as a loader or dropper, responsible for delivering and executing other malicious payloads on the compromised systems. This modular approach allows the attackers to adapt their tactics and deploy different tools as needed, increasing the complexity and resilience of their operations. BINDCLOAK, on the other hand, is described as a DNS tunneling tool. DNS tunneling is a technique that abuses the Domain Name System (DNS) protocol to transmit data. Attackers use it to bypass firewalls and network security measures by encoding data within DNS queries and responses, making it difficult to distinguish malicious traffic from legitimate network activity. The combination of these malware families suggests a well-resourced and sophisticated adversary capable of executing multi-stage attacks.
Zscaler ThreatLabz's analysis indicates that the primary objective of this campaign is likely espionage and data theft, given the targeting of government entities. The specific nature of the data sought remains under investigation, but such attacks often aim to acquire sensitive state secrets, intelligence, or personal information of government officials. The attribution to an East Asian threat actor, while not naming a specific nation-state, points to a geopolitical context that may be driving these cyber operations. The firm's detection of this campaign earlier this month underscores the ongoing and evolving nature of cyber threats, emphasizing the need for continuous vigilance and advanced threat detection capabilities for organizations, particularly those in sensitive sectors like government and critical infrastructure.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.