< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-27T14:18:47+05:30

TELESHIM Malware Campaign Utilizes Telegram for C2 in Middle East Government Attacks

A threat actor linked to East Asia is using the TELESHIM malware family to conduct cyberattacks against Middle East governments, leveraging Telegram's API for command-and-control (C2) communications to evade detection. The campaign employs advanced obfuscation techniques, DLL sideloading, and environmental keying to target specific systems and maintain persistence.

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.

The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.

Read original article

*** END OF TRANSMISSION ***