A sophisticated cyberattack has been discovered utilizing Telegram bots to stealthily manage backdoors within Middle Eastern government networks. This operation cleverly uses standard Windows components and seemingly benign files, allowing attackers to infiltrate systems without raising immediate suspicion.
Details of the Cyber Espionage Campaign
The attack initiates with an ISO image containing a legitimate ASUSTek RegSchdTask.exe program alongside a malicious DLL. Once executed, the program activates the attacker’s code, setting off a multi-layered intrusion process that eventually deploys TELESHIM, MIXEDKEY, and BINDCLOAK implants.
TELESHIM cleverly uses Telegram’s Bot API as a command channel, making its malicious activities appear like normal communications with a trusted service. Cybersecurity researchers from Zscaler identified this activity in July 2026, linking it to actors from East Asia targeting governmental entities in the Middle East.
Intrusion Techniques and Persistence
The attackers used TELESHIM as an initial backdoor, which connects to Telegram to receive commands directed at the compromised system’s unique network identifier. This approach allows operators to discreetly manage the infected systems without directly connecting to suspicious servers.
TELESHIM also facilitates file transfers via the bot interface, decrypting and executing them locally using scheduled tasks. This combination reflects techniques used in persistence attacks, where malware can reappear after a system restart.
The backdoor incorporates several strategies to evade detection, such as checking for virtualized environments and conducting extensive disk activity to hinder automated scans and manual analysis.
Advanced Attack Chain and Defensive Measures
Following initial access, the attackers conducted comprehensive reconnaissance, understanding system, user, network, and file details to tailor their approach. Using a method known as sideloading, they deployed a legitimate executable with a malicious DLL to progress the attack.
The second-stage loader, MIXEDKEY, decrypts payloads using the device’s volume serial number, ensuring the malware is specific to its intended victim. The final payload, BINDCLOAK, communicates with a domain controlled by the attackers, furthering the infiltration.
Zscaler’s assessment suggests a probable East Asian origin of the attackers, though no specific threat group has been identified. Security teams are advised to monitor for unexpected ISO files, unusual DLL loading, and abnormal Telegram API traffic, especially in environments where the messaging service is not typically used.
Strengthening defenses involves reviewing signs of DLL sideloading malware and investigating any unexpected scheduled tasks. Proactive threat detection and rapid response measures are crucial in countering such sophisticated cyber threats.
