An unaffiliated East Asian threat actor has been conducting cyber attacks against Middle Eastern government entities, deploying TELESHIM, MIXEDKEY, and BINDCLOAK malware. The actor uses Telegram for C2 and operates primarily during UTC morning hours.