Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TELESHIM Exploits Telegram for C2 in Middle East Attacks

TELESHIM Exploits Telegram for C2 in Middle East Attacks

Posted on July 27, 2026 By CWS

In a recent revelation, cybersecurity experts have identified a series of cyber attacks targeting governmental bodies in the Middle East, orchestrated by a threat actor linked to East Asia. The campaign has introduced several new malware families, primarily TELESHIM, MIXEDKEY, and BINDCLOAK, as reported by Zscaler ThreatLabz. This activity was detected earlier in the month.

TELESHIM’s Multi-Stage Attack Strategy

The operation employs a complex multi-stage attack chain to infiltrate and persist on compromised systems. TELESHIM, a key component of the attack, leverages the Telegram API for command-and-control (C2) communications, making its traffic appear legitimate, according to Sudeep Singh, a senior manager at Zscaler ThreatLabz. This was detailed in a technical report released last week.

The initial phase of the attack is initiated through an ISO file containing a legitimate executable, ‘RegSchdTask.exe,’ which sideloads a malicious DLL, ‘AsTaskSched.dll.’ This DLL operates as a Windows backdoor, utilizing Telegram for C2 activities to manage further stages of the attack.

Complex Malware Techniques and Encryption

Further in the chain, additional payloads execute another DLL sideloading process involving ‘GoProAlertService.exe’ and ‘pthreadVC2.dll.’ The latter acts as a reflective loader named MIXEDKEY that decrypts and implements the malicious contents of a specific file. Both TELESHIM and MIXEDKEY employ sophisticated obfuscation methods to challenge reverse engineering attempts.

TELESHIM is designed to detect virtualization-based analysis environments using techniques like CPUID for hypervisor detection and WMI for RAM speed checks. Its C2 communications involve sending control messages to register infected hosts and downloading secondary payloads executed as scheduled tasks.

Implications and Attribution of the Cyber Threat

The final payload is protected by two layers of XOR encryption, ensuring it only activates on intended targets through environmental keying. This culminates in deploying BINDCLOAK, a C++-based implant that connects to an external server for post-compromise activities.

ThreatLabz observed activity from the C2 operator involving reconnaissance and payload distribution between July 7 and July 9, 2026, predominantly executed between 4 a.m. and 12 p.m. UTC. Analysis of operational patterns, IP geolocation, and system locale suggests the involvement of a threat actor from East Asia, although no specific group has been identified yet.

This incident underscores broader cybersecurity trends such as evading Endpoint Detection and Response (EDR) systems, blending malicious traffic with legitimate sources, and employing advanced code obfuscation techniques to thwart reverse engineering, Singh noted.

The Hacker News Tags:C2 communication, cyber attacks, Cybersecurity, East Asia, Malware, malware obfuscation, Middle East, Telegram, TELESHIM, Zscaler ThreatLabz

Post navigation

Previous Post: PyPI Restricts Older Release File Uploads to Boost Security
Next Post: DentaQuest Data Breach Affects Millions Nationwide

Related Posts

New Malspam Campaign Exploits Google DoubleClick New Malspam Campaign Exploits Google DoubleClick The Hacker News
NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI Servers NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI Servers The Hacker News
Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams Zero-Day Exploits, Developer Malware, IoT Botnets, and AI-Powered Scams The Hacker News
Anthropic Launches Claude AI for Healthcare with Secure Health Record Access Anthropic Launches Claude AI for Healthcare with Secure Health Record Access The Hacker News
Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & More The Hacker News
APT28 Deploys BEARDSHELL and COVENANT in Ukraine Espionage APT28 Deploys BEARDSHELL and COVENANT in Ukraine Espionage The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows 11 Boosts File Explorer Speed for Large Deletions
  • Anthropic’s Opus 5: A Budget-Friendly Cybersecurity Model
  • GitHub Introduces Dependabot Cooldown to Curb Threats
  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows 11 Boosts File Explorer Speed for Large Deletions
  • Anthropic’s Opus 5: A Budget-Friendly Cybersecurity Model
  • GitHub Introduces Dependabot Cooldown to Curb Threats
  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark