Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TELESHIM Exploits Telegram for C2 in Middle East Attacks

TELESHIM Exploits Telegram for C2 in Middle East Attacks

Posted on July 27, 2026 By CWS

In a recent revelation, cybersecurity experts have identified a series of cyber attacks targeting governmental bodies in the Middle East, orchestrated by a threat actor linked to East Asia. The campaign has introduced several new malware families, primarily TELESHIM, MIXEDKEY, and BINDCLOAK, as reported by Zscaler ThreatLabz. This activity was detected earlier in the month.

TELESHIM’s Multi-Stage Attack Strategy

The operation employs a complex multi-stage attack chain to infiltrate and persist on compromised systems. TELESHIM, a key component of the attack, leverages the Telegram API for command-and-control (C2) communications, making its traffic appear legitimate, according to Sudeep Singh, a senior manager at Zscaler ThreatLabz. This was detailed in a technical report released last week.

The initial phase of the attack is initiated through an ISO file containing a legitimate executable, ‘RegSchdTask.exe,’ which sideloads a malicious DLL, ‘AsTaskSched.dll.’ This DLL operates as a Windows backdoor, utilizing Telegram for C2 activities to manage further stages of the attack.

Complex Malware Techniques and Encryption

Further in the chain, additional payloads execute another DLL sideloading process involving ‘GoProAlertService.exe’ and ‘pthreadVC2.dll.’ The latter acts as a reflective loader named MIXEDKEY that decrypts and implements the malicious contents of a specific file. Both TELESHIM and MIXEDKEY employ sophisticated obfuscation methods to challenge reverse engineering attempts.

TELESHIM is designed to detect virtualization-based analysis environments using techniques like CPUID for hypervisor detection and WMI for RAM speed checks. Its C2 communications involve sending control messages to register infected hosts and downloading secondary payloads executed as scheduled tasks.

Implications and Attribution of the Cyber Threat

The final payload is protected by two layers of XOR encryption, ensuring it only activates on intended targets through environmental keying. This culminates in deploying BINDCLOAK, a C++-based implant that connects to an external server for post-compromise activities.

ThreatLabz observed activity from the C2 operator involving reconnaissance and payload distribution between July 7 and July 9, 2026, predominantly executed between 4 a.m. and 12 p.m. UTC. Analysis of operational patterns, IP geolocation, and system locale suggests the involvement of a threat actor from East Asia, although no specific group has been identified yet.

This incident underscores broader cybersecurity trends such as evading Endpoint Detection and Response (EDR) systems, blending malicious traffic with legitimate sources, and employing advanced code obfuscation techniques to thwart reverse engineering, Singh noted.

The Hacker News Tags:C2 communication, cyber attacks, Cybersecurity, East Asia, Malware, malware obfuscation, Middle East, Telegram, TELESHIM, Zscaler ThreatLabz

Post navigation

Previous Post: PyPI Restricts Older Release File Uploads to Boost Security
Next Post: DentaQuest Data Breach Affects Millions Nationwide

Related Posts

Canadian Arrested for Operating Kimwolf DDoS Botnet Canadian Arrested for Operating Kimwolf DDoS Botnet The Hacker News
Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games The Hacker News
Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict The Hacker News
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch The Hacker News
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor The Hacker News
China-Based APT UAT-7810 Enhances ORB Network with LONGLEASH China-Based APT UAT-7810 Enhances ORB Network with LONGLEASH The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide
  • TELESHIM Exploits Telegram for C2 in Middle East Attacks
  • PyPI Restricts Older Release File Uploads to Boost Security
  • Critical ChatGPT AgentForger Exploit Fixed by OpenAI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SparkKitty Targets Crypto Users via Photo Scanning
  • DentaQuest Data Breach Affects Millions Nationwide
  • TELESHIM Exploits Telegram for C2 in Middle East Attacks
  • PyPI Restricts Older Release File Uploads to Boost Security
  • Critical ChatGPT AgentForger Exploit Fixed by OpenAI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark