Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyberattack Turns Telegram Bots Into Covert Control System

Cyberattack Turns Telegram Bots Into Covert Control System

Posted on July 21, 2026 By CWS

A sophisticated cyberattack has been discovered utilizing Telegram bots to stealthily manage backdoors within Middle Eastern government networks. This operation cleverly uses standard Windows components and seemingly benign files, allowing attackers to infiltrate systems without raising immediate suspicion.

Details of the Cyber Espionage Campaign

The attack initiates with an ISO image containing a legitimate ASUSTek RegSchdTask.exe program alongside a malicious DLL. Once executed, the program activates the attacker’s code, setting off a multi-layered intrusion process that eventually deploys TELESHIM, MIXEDKEY, and BINDCLOAK implants.

TELESHIM cleverly uses Telegram’s Bot API as a command channel, making its malicious activities appear like normal communications with a trusted service. Cybersecurity researchers from Zscaler identified this activity in July 2026, linking it to actors from East Asia targeting governmental entities in the Middle East.

Intrusion Techniques and Persistence

The attackers used TELESHIM as an initial backdoor, which connects to Telegram to receive commands directed at the compromised system’s unique network identifier. This approach allows operators to discreetly manage the infected systems without directly connecting to suspicious servers.

TELESHIM also facilitates file transfers via the bot interface, decrypting and executing them locally using scheduled tasks. This combination reflects techniques used in persistence attacks, where malware can reappear after a system restart.

The backdoor incorporates several strategies to evade detection, such as checking for virtualized environments and conducting extensive disk activity to hinder automated scans and manual analysis.

Advanced Attack Chain and Defensive Measures

Following initial access, the attackers conducted comprehensive reconnaissance, understanding system, user, network, and file details to tailor their approach. Using a method known as sideloading, they deployed a legitimate executable with a malicious DLL to progress the attack.

The second-stage loader, MIXEDKEY, decrypts payloads using the device’s volume serial number, ensuring the malware is specific to its intended victim. The final payload, BINDCLOAK, communicates with a domain controlled by the attackers, furthering the infiltration.

Zscaler’s assessment suggests a probable East Asian origin of the attackers, though no specific threat group has been identified. Security teams are advised to monitor for unexpected ISO files, unusual DLL loading, and abnormal Telegram API traffic, especially in environments where the messaging service is not typically used.

Strengthening defenses involves reviewing signs of DLL sideloading malware and investigating any unexpected scheduled tasks. Proactive threat detection and rapid response measures are crucial in countering such sophisticated cyber threats.

Cyber Security News Tags:Backdoor, Botnet, cyber espionage, Cyberattack, Cybersecurity, DLL Sideloading, East Asia, government networks, ISO image, Malware, network security, scheduled tasks, Telegram bots, threat detection, Zscaler

Post navigation

Previous Post: Furtex: Advanced Linux Toolkit for Security Experts
Next Post: Integrating CBOM Solutions in Modern Architecture

Related Posts

New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials New Lampion Stealer Uses ClickFix Attack to Silently Steal Login Credentials Cyber Security News
DevilNFC Malware Traps Victims in Fake Banking Screens DevilNFC Malware Traps Victims in Fake Banking Screens Cyber Security News
Cyber Group Claims Massive Data Breach at Odido Cyber Group Claims Massive Data Breach at Odido Cyber Security News
Palo Alto Networks to Acquire CyberArk in  Billion Deal Palo Alto Networks to Acquire CyberArk in $25 Billion Deal Cyber Security News
Critical Cisco SD-WAN Flaw Allows Root Command Execution Critical Cisco SD-WAN Flaw Allows Root Command Execution Cyber Security News
DesckVB RAT 2.9: Advanced Threat with Modular Plugins DesckVB RAT 2.9: Advanced Threat with Modular Plugins Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark