Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TELESHIM Exploits Telegram for C2 in Middle East Attacks

TELESHIM Exploits Telegram for C2 in Middle East Attacks

Posted on July 27, 2026 By CWS

In a recent revelation, cybersecurity experts have identified a series of cyber attacks targeting governmental bodies in the Middle East, orchestrated by a threat actor linked to East Asia. The campaign has introduced several new malware families, primarily TELESHIM, MIXEDKEY, and BINDCLOAK, as reported by Zscaler ThreatLabz. This activity was detected earlier in the month.

TELESHIM’s Multi-Stage Attack Strategy

The operation employs a complex multi-stage attack chain to infiltrate and persist on compromised systems. TELESHIM, a key component of the attack, leverages the Telegram API for command-and-control (C2) communications, making its traffic appear legitimate, according to Sudeep Singh, a senior manager at Zscaler ThreatLabz. This was detailed in a technical report released last week.

The initial phase of the attack is initiated through an ISO file containing a legitimate executable, ‘RegSchdTask.exe,’ which sideloads a malicious DLL, ‘AsTaskSched.dll.’ This DLL operates as a Windows backdoor, utilizing Telegram for C2 activities to manage further stages of the attack.

Complex Malware Techniques and Encryption

Further in the chain, additional payloads execute another DLL sideloading process involving ‘GoProAlertService.exe’ and ‘pthreadVC2.dll.’ The latter acts as a reflective loader named MIXEDKEY that decrypts and implements the malicious contents of a specific file. Both TELESHIM and MIXEDKEY employ sophisticated obfuscation methods to challenge reverse engineering attempts.

TELESHIM is designed to detect virtualization-based analysis environments using techniques like CPUID for hypervisor detection and WMI for RAM speed checks. Its C2 communications involve sending control messages to register infected hosts and downloading secondary payloads executed as scheduled tasks.

Implications and Attribution of the Cyber Threat

The final payload is protected by two layers of XOR encryption, ensuring it only activates on intended targets through environmental keying. This culminates in deploying BINDCLOAK, a C++-based implant that connects to an external server for post-compromise activities.

ThreatLabz observed activity from the C2 operator involving reconnaissance and payload distribution between July 7 and July 9, 2026, predominantly executed between 4 a.m. and 12 p.m. UTC. Analysis of operational patterns, IP geolocation, and system locale suggests the involvement of a threat actor from East Asia, although no specific group has been identified yet.

This incident underscores broader cybersecurity trends such as evading Endpoint Detection and Response (EDR) systems, blending malicious traffic with legitimate sources, and employing advanced code obfuscation techniques to thwart reverse engineering, Singh noted.

The Hacker News Tags:C2 communication, cyber attacks, Cybersecurity, East Asia, Malware, malware obfuscation, Middle East, Telegram, TELESHIM, Zscaler ThreatLabz

Post navigation

Previous Post: PyPI Restricts Older Release File Uploads to Boost Security
Next Post: DentaQuest Data Breach Affects Millions Nationwide

Related Posts

GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms The Hacker News
Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing The Hacker News
China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023 China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023 The Hacker News
New Exploit Targets On-Prem Microsoft Exchange Servers New Exploit Targets On-Prem Microsoft Exchange Servers The Hacker News
Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet The Hacker News
Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark