In a recent revelation, cybersecurity experts have identified a series of cyber attacks targeting governmental bodies in the Middle East, orchestrated by a threat actor linked to East Asia. The campaign has introduced several new malware families, primarily TELESHIM, MIXEDKEY, and BINDCLOAK, as reported by Zscaler ThreatLabz. This activity was detected earlier in the month.
TELESHIM’s Multi-Stage Attack Strategy
The operation employs a complex multi-stage attack chain to infiltrate and persist on compromised systems. TELESHIM, a key component of the attack, leverages the Telegram API for command-and-control (C2) communications, making its traffic appear legitimate, according to Sudeep Singh, a senior manager at Zscaler ThreatLabz. This was detailed in a technical report released last week.
The initial phase of the attack is initiated through an ISO file containing a legitimate executable, ‘RegSchdTask.exe,’ which sideloads a malicious DLL, ‘AsTaskSched.dll.’ This DLL operates as a Windows backdoor, utilizing Telegram for C2 activities to manage further stages of the attack.
Complex Malware Techniques and Encryption
Further in the chain, additional payloads execute another DLL sideloading process involving ‘GoProAlertService.exe’ and ‘pthreadVC2.dll.’ The latter acts as a reflective loader named MIXEDKEY that decrypts and implements the malicious contents of a specific file. Both TELESHIM and MIXEDKEY employ sophisticated obfuscation methods to challenge reverse engineering attempts.
TELESHIM is designed to detect virtualization-based analysis environments using techniques like CPUID for hypervisor detection and WMI for RAM speed checks. Its C2 communications involve sending control messages to register infected hosts and downloading secondary payloads executed as scheduled tasks.
Implications and Attribution of the Cyber Threat
The final payload is protected by two layers of XOR encryption, ensuring it only activates on intended targets through environmental keying. This culminates in deploying BINDCLOAK, a C++-based implant that connects to an external server for post-compromise activities.
ThreatLabz observed activity from the C2 operator involving reconnaissance and payload distribution between July 7 and July 9, 2026, predominantly executed between 4 a.m. and 12 p.m. UTC. Analysis of operational patterns, IP geolocation, and system locale suggests the involvement of a threat actor from East Asia, although no specific group has been identified yet.
This incident underscores broader cybersecurity trends such as evading Endpoint Detection and Response (EDR) systems, blending malicious traffic with legitimate sources, and employing advanced code obfuscation techniques to thwart reverse engineering, Singh noted.
