Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyberattack Turns Telegram Bots Into Covert Control System

Cyberattack Turns Telegram Bots Into Covert Control System

Posted on July 21, 2026 By CWS

A sophisticated cyberattack has been discovered utilizing Telegram bots to stealthily manage backdoors within Middle Eastern government networks. This operation cleverly uses standard Windows components and seemingly benign files, allowing attackers to infiltrate systems without raising immediate suspicion.

Details of the Cyber Espionage Campaign

The attack initiates with an ISO image containing a legitimate ASUSTek RegSchdTask.exe program alongside a malicious DLL. Once executed, the program activates the attacker’s code, setting off a multi-layered intrusion process that eventually deploys TELESHIM, MIXEDKEY, and BINDCLOAK implants.

TELESHIM cleverly uses Telegram’s Bot API as a command channel, making its malicious activities appear like normal communications with a trusted service. Cybersecurity researchers from Zscaler identified this activity in July 2026, linking it to actors from East Asia targeting governmental entities in the Middle East.

Intrusion Techniques and Persistence

The attackers used TELESHIM as an initial backdoor, which connects to Telegram to receive commands directed at the compromised system’s unique network identifier. This approach allows operators to discreetly manage the infected systems without directly connecting to suspicious servers.

TELESHIM also facilitates file transfers via the bot interface, decrypting and executing them locally using scheduled tasks. This combination reflects techniques used in persistence attacks, where malware can reappear after a system restart.

The backdoor incorporates several strategies to evade detection, such as checking for virtualized environments and conducting extensive disk activity to hinder automated scans and manual analysis.

Advanced Attack Chain and Defensive Measures

Following initial access, the attackers conducted comprehensive reconnaissance, understanding system, user, network, and file details to tailor their approach. Using a method known as sideloading, they deployed a legitimate executable with a malicious DLL to progress the attack.

The second-stage loader, MIXEDKEY, decrypts payloads using the device’s volume serial number, ensuring the malware is specific to its intended victim. The final payload, BINDCLOAK, communicates with a domain controlled by the attackers, furthering the infiltration.

Zscaler’s assessment suggests a probable East Asian origin of the attackers, though no specific threat group has been identified. Security teams are advised to monitor for unexpected ISO files, unusual DLL loading, and abnormal Telegram API traffic, especially in environments where the messaging service is not typically used.

Strengthening defenses involves reviewing signs of DLL sideloading malware and investigating any unexpected scheduled tasks. Proactive threat detection and rapid response measures are crucial in countering such sophisticated cyber threats.

Cyber Security News Tags:Backdoor, Botnet, cyber espionage, Cyberattack, Cybersecurity, DLL Sideloading, East Asia, government networks, ISO image, Malware, network security, scheduled tasks, Telegram bots, threat detection, Zscaler

Post navigation

Previous Post: Furtex: Advanced Linux Toolkit for Security Experts
Next Post: Integrating CBOM Solutions in Modern Architecture

Related Posts

Chinese Hackers Use AI Tools in Sophisticated Cyberattacks Chinese Hackers Use AI Tools in Sophisticated Cyberattacks Cyber Security News
RapperBot Hijacking Devices to Launch DDoS Attack In a Split Second RapperBot Hijacking Devices to Launch DDoS Attack In a Split Second Cyber Security News
ChatGPT Down – Users Report Outage Worldwide, Conversations Disappeared for Users ChatGPT Down – Users Report Outage Worldwide, Conversations Disappeared for Users Cyber Security News
Microsoft’s New Teams New Admin Role to Manage External Collaboration Settings Microsoft’s New Teams New Admin Role to Manage External Collaboration Settings Cyber Security News
Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials Cyber Security News
Urgent Alert: Craft CMS Vulnerability Under Attack Urgent Alert: Craft CMS Vulnerability Under Attack Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark