← Back to Feed
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
July 27, 2026 · The Hacker News · Severity: HIGH
A threat actor with ties to East Asia is targeting Middle Eastern government entities using a multi-stage attack chain deploying TELESHIM, MIXEDKEY, and BINDCLOAK malware families. Zscaler ThreatLabz detected the campaign with TELESHIM abusing the Telegram API for C2 communication to blend with legitimate traffic. The attack chain starts with an ISO file using DLL side-loading to deploy a 32-bit Windows backdoor that leverages Telegram for command and control.
Key Takeaways
- East Asia-linked threat actor targets Middle East governments with TELESHIM, MIXEDKEY, and BINDCLOAK malware.
- TELESHIM abuses Telegram API for command-and-control to blend with legitimate internet traffic.
- Attack chain uses ISO files and DLL side-loading to deploy a 32-bit Windows backdoor.